OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
Moderate severity
GitHub Reviewed
Published
Mar 24, 2026
in
openclaw/openclaw
•
Updated Mar 26, 2026
Description
Published to the GitHub Advisory Database
Mar 26, 2026
Reviewed
Mar 26, 2026
Last updated
Mar 26, 2026
Summary
Tlon cite expansion happened before channel and DM authorization completed, allowing cite work and content handling before the final auth decision.
Affected Packages / Versions
openclaw(npm)v2026.3.23-2(630f1479c44f78484dfa21bb407cbe6f171dac87)2026.3.23-2Fix Commit(s)
3cbf932413e41d1836cb91aed1541a28a3122f93ebee4e2210e1f282a982c7ef2ad79d77a572fc87Release Status
The fix shipped in
v2026.3.22and remains present inv2026.3.23andv2026.3.23-2.Code-Level Confirmation
OpenClaw thanks @zpbrent for reporting.
References