<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Openclaw/Whatsapp (&lt; 2026.8.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@openclaw/whatsapp--2026.8.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 06:57:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@openclaw/whatsapp--2026.8.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in @openclaw/whatsapp npm package</title><link>https://feed.craftedsignal.io/briefs/2026-09-openclaw-whatsapp-auth-bypass/</link><pubDate>Sat, 26 Sep 2026 06:57:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openclaw-whatsapp-auth-bypass/</guid><description>The @openclaw/whatsapp npm package prior to version 2026.8.1 contains an authorization bypass vulnerability (CVE-2026-100532) allowing non-owner users to trigger the WhatsApp login tool, resulting in service disruption via account disconnection.</description><content:encoded><![CDATA[<p>The @openclaw/whatsapp npm package, used for integrating WhatsApp functionality, contains a critical authorization flaw (CVE-2026-100532) in versions prior to 2026.8.1. The vulnerability stems from a failure to enforce the 'owner-only' security boundary on the generic channel-tool path used for the WhatsApp login process.</p>
<p>By design, the login tool should only be accessible to the configured owner of the service. However, because the tool fails to preserve or validate the sender's owner status during the interaction, any non-owner user capable of steering the tool can invoke the login functionality. This action forces the service to generate a new QR code for a configured account. This process effectively disconnects the currently active WhatsApp account from the Gateway, leading to a denial-of-service condition. While the primary impact is service disruption, an attacker with physical access to the device can perform a subsequent QR code scan to relink the gateway to an account of their choosing, leading to unauthorized account control.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to immediate denial-of-service as the active WhatsApp account is disconnected from the Gateway. In scenarios where an attacker can scan the newly generated QR code, they can hijack the gateway's WhatsApp integration. This vulnerability affects all environments deploying @openclaw/whatsapp versions earlier than 2026.8.1.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade the @openclaw/whatsapp dependency to version 2026.8.1 or later.</li>
<li>Audit logs for unauthorized access attempts to the login tool path or unexpected QR code generation events triggered by non-administrative service accounts.</li>
<li>Implement stricter access control logic at the application layer if upgrading is delayed, ensuring only authorized user IDs are permitted to interact with the channel-tool path.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>npm</category><category>supply-chain</category></item></channel></rss>