5.3 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
OpenClaw Discord before 2026.7.1 Authorization Bypass
OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.
References
-
GitHub Security Advisory (GHSA-35wj-hm2r-ghgw) vendor-advisory
-
VulnCheck Advisory: OpenClaw Discord before 2026.7.1 Authorization Bypass third-party-advisory
Affected products
- ==2026.7.1
- <2026.7.1
Matching in nixpkgs
pkgs.discord
All-in-one cross-platform voice and text chat for gamers
pkgs.discordo
Lightweight, secure, and feature-rich Discord terminal client
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2026-08-18
-
nixos-26.05 -
- nixos-26.05-small 0-unstable-2026-05-12
pkgs.discord-sh
Write-only command-line Discord webhook integration written in 100% Bash script
pkgs.discord-ptb
All-in-one cross-platform voice and text chat for gamers
pkgs.discord-rpc
Official library to interface with the Discord client
pkgs.discord-canary
All-in-one cross-platform voice and text chat for gamers
pkgs.bitlbee-discord
Bitlbee plugin for Discord
pkgs.discord-gamesdk
Library to allow other programs to interact with the Discord desktop application
pkgs.mautrix-discord
Matrix-Discord puppeting bridge
pkgs.mpd-discord-rpc
Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence
pkgs.betterdiscordctl
Utility for managing BetterDiscord on Linux
pkgs.music-discord-rpc
Cross-platform Discord rich presence for music with album cover and progress bar support
pkgs.catppuccin-discord
Soothing pastel theme for Discord
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2024-12-08
-
nixos-26.05 -
- nixos-26.05-small 0-unstable-2024-12-08
pkgs.discord-development
All-in-one cross-platform voice and text chat for gamers
pkgs.zed-discord-presence
Discord rich presence for Zed
pkgs.mpvScripts.mpv-discord
Cross-platform Discord Rich Presence integration for mpv with no external dependencies
pkgs.betterdiscord-installer
Installer for BetterDiscord
pkgs.discordchatexporter-cli
Tool to export Discord chat logs to a file
pkgs.matrix-appservice-discord
None
-
nixos-26.05 -
- nixos-26.05-small 4.0.0
pkgs.discord-rich-presence-plex
Displays your Plex status on Discord using Rich Presence
pkgs.discordchatexporter-desktop
Tool to export Discord chat logs to a file (GUI version)
pkgs.python313Packages.discordpy
Python wrapper for the Discord API
pkgs.python314Packages.discordpy
Python wrapper for the Discord API
pkgs.pidginPackages.purple-discord
Discord plugin for Pidgin
-
nixos-unstable -
- nixos-unstable-small 2021-10-17
-
nixos-26.05 -
- nixos-26.05-small 2021-10-17
pkgs.haskellPackages.discord-haskell
Write bots for Discord in Haskell
pkgs.keycloakPlugins.keycloak-discord
Keycloak Identity Provider extension for Discord
-
nixos-unstable -
- nixos-unstable-small 1.3.1
pkgs.python313Packages.discord-webhook
Execute discord webhooks
pkgs.python314Packages.discord-webhook
Execute discord webhooks
pkgs.navidromePlugins.discord-rich-presence
None
-
nixos-26.05 -
- nixos-26.05-small 2.0.0
Package maintainers
-
@chillcicada chillcicada <2210227279@qq.com>
-
@Lassulus Lassulus <lassulus@gmail.com>
-
@NotAShelf NotAShelf <raf@notashelf.dev>
-
@Infinidoge Infinidoge <infinidoge@inx.moe>
-
@4evy 4evy <git@evy.pink>
-
@Scrumplex Sefa Eyeoglu <contact@scrumplex.net>
-
@sophiebsw Sophia <nixpkgs@drifter.dev>
-
@Artturin Artturi N <artturin@artturin.com>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@tomodachi94 Tomodachi94 <tomodachi94@protonmail.com>
-
@hogcycle hogcycle <nate@gysli.ng>
-
@MatthewCroughan Matthew Croughan <matt@croughan.sh>
-
@phanirithvij Phani Rithvij <phanirithvij2000@gmail.com>
-
@kek5chen Willow <git@willow.moe>
-
@philocalyst Myles Wirth <milestheperson@posteo.net>
-
@Arian-D Arian Dehghani <arianxdehghani@gmail.com>
-
@siphc siphc <ayfpan@ucla.edu>
-
@sumnerevans Sumner Evans <me@sumnerevans.com>
-
@bddvlpr Luna Simons <luna@bddvlpr.com>
-
@S-NA S. Nordin Abouzahra <abouzahra.9@wright.edu>
-
@polyfloyd polyfloyd <floyd@polyfloyd.net>
-
@GetPsyched Priyanshu Tripathi <nixos@getpsyched.dev>
-
@ap-1 Anish Pallati <i@anish.land>
-
@mkg20001 Maciej Krüger <mkg20001+nix@gmail.com>