OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media sto…
中危 CVSS 6.5
摘要
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subsequently rejected.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/openclaw/openclaw/commit/68ceaf7a5f64a23e78b95eff055e4b497218312a Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-v2v2-f783-358j Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-unauthorized-media-download-via-zalo-channel Third Party Advisory
时间线
- nvd_ingest NVD