Junglewise Threat Intelligence

OpenClaw Telegram access control bypass in media download

Severity: info · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Telegram bot integration library used to automate messaging and media handling. A flaw in direct message (DM) handling allows unauthorized users to trigger downloads and disk writes of media files before access checks are enforced, potentially exhausting disk space or exposing the application to resource exhaustion attacks.

Technical details

The vulnerability is an access control bypass in the Telegram handler where inbound media files (including media groups) are downloaded and written to disk before sender authorization checks complete. An attacker can send media to the bot in DM mode even when they lack permission, triggering disk I/O and resource allocation. The root cause is a missing authorization gate before media processing. The attack requires only network access to send a Telegram DM to the bot and no authentication. An attacker can cause unwanted disk writes, exhaust storage, or trigger resource exhaustion (CWE-770, CWE-406). The fix, released in version 2026.2.24, enforces DM authorization checks before any media download or write paths execute.

Affected products

  • OpenClaw openclaw <= 2026.2.23

Timeline

  • 2026-02-25: disclosed: Advisory published on GitHub; fix released as openclaw@2026.2.24 on npm
  • 2026-03-03: other: Advisory indexed in OSV database

References

Related threats