
Cloud Vulnerability DB
A community-led vulnerabilities database
OpenClaw Matrix DM allowlist matching could be bypassed in certain configurations. Matrix support ships as an optional plugin (not bundled with the core install), so this only affects deployments that have installed and enabled the Matrix plugin.
openclaw (npm)>= 2026.1.14-1, < 2026.2.2>= 2026.2.2In affected versions, DM allowlist decisions could be made by exact-matching channels.matrix.dm.allowFrom entries against multiple sender-derived candidates, including:
@alice:evil.example and @alice:trusted.example both match alice
If an operator configured channels.matrix.dm.allowFrom with display names or bare localparts (for example, "Alice" or "alice"), a remote Matrix user may be able to impersonate an allowed identity for allowlist purposes and reach the routing/agent pipeline.Matrix DM allowlist identity confusion. The practical impact depends on your Matrix channel policies and what capabilities are enabled downstream.
openclaw >= 2026.2.2.@user:server (or *). Do not use display names or bare localparts.8f3bfbd1c4fb967a2ddb5b4b9a05784920814bcfThe patched version is already published to npm; the advisory can be published once you're ready. Thanks @MegaManSec (https://joshua.hu) of AISLE Research Team for reporting.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."