Incorrect authorization in OpenClaw - #VU125208
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify session state.
The vulnerability exists due to incorrect authorization in Telegram direct message inline button callback handling when processing callback queries from direct messages. A remote user can send a crafted callback query to modify session state.
The issue occurs because normal direct message pairing requirements are not enforced for these callbacks.