#VU125207 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass DM policy restrictions and send verification notices to unpaired peers.
The vulnerability exists due to incorrect authorization in matrix verification notices when sending verification notices in direct messages. A remote user can send a verification notice to a peer outside the allowed DM policy to bypass DM policy restrictions and send verification notices to unpaired peers.