OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback
Moderate severity
GitHub Reviewed
Published
Mar 26, 2026
in
openclaw/openclaw
•
Updated Mar 29, 2026
Description
Published to the GitHub Advisory Database
Mar 29, 2026
Reviewed
Mar 29, 2026
Last updated
Mar 29, 2026
Summary
MS Teams Feedback Invoke Bypasses Sender Allowlists and Records Unauthorized Session Feedback
Affected Packages / Versions
openclaw<= 2026.3.242026.3.252026.3.24Details
Microsoft Teams feedback invokes previously bypassed sender authorization and could record feedback or trigger reflection for unauthorized senders. Commit
c5415a474bb085404c20f8b312e436997977b1eaapplies the same DM and group authorization checks to feedback invokes.Verified vulnerable on tag
v2026.3.24and fixed onmainby commitc5415a474bb085404c20f8b312e436997977b1ea.Fix Commit(s)
c5415a474bb085404c20f8b312e436997977b1eaReferences