Authorization bypass through user-controlled key in OpenClaw - #VU128769
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to interfere with another conversation's pending file upload.
The vulnerability exists due to authorization bypass through user-controlled key in the MS Teams file-consent invoke handler when processing fileConsent/invoke requests using an uploadId without verifying the originating conversation. A remote attacker can submit a valid uploadId within its time-to-live to interfere with another conversation's pending file upload.
The issue affects both the accept path for cross-conversation upload completion and the decline path for canceling a victim pending upload.