Executive brief
OpenClaw's BlueBubbles extension handles group messaging and reaction features in a chat application. A flaw in the group reactions feature allowed users to bypass mention-gating controls, enabling them to send reactions (emoji responses) in groups that were supposed to restrict posting to mentioned users only. Attackers could trigger system events visible to chat agents without proper authorization, potentially exposing unintended notifications or actions.
Technical details
The vulnerability is an authorization bypass (CWE-863) and authentication bypass via alternate path (CWE-288) in the BlueBubbles group reactions handler. Group messages were protected by a "requireMention" gate that enforced authorization rules, but the reaction event path did not apply the same checks before enqueuing system events. An authenticated actor with network access to a BlueBubbles group could submit a reaction that would bypass the mention gate and trigger agent-visible system events in mention-gated groups. Fix commit f8c98630785288cc1f1d0893503ef3b653a3cede aligns the reaction code path with the standard message authorization logic. The vulnerability affected versions up to 2026.3.24; version 2026.3.25 contains the patch.
Affected products
- OpenClaw BlueBubbles ≤ 2026.3.24
Timeline
- 2026-03-27: disclosed
- 2026-03-25: patched: Version 2026.3.25 patches the vulnerability; fix commit f8c98630785288cc1f1d0893503ef3b653a3cede