Junglewise Threat Intelligence

CVE-2026-32021: OpenClaw Feishu allowFrom authorization bypass via display-name collision

CVE-2026-32021 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a library that handles messaging integrations, including Feishu (a workplace communication platform). The software's allowlist feature was supposed to restrict message delivery to authorized sender IDs, but an attacker could bypass this restriction by setting their display name to match an allowlisted ID, gaining unauthorized access to protected communication channels.

Technical details

The vulnerability is an authorization bypass in the Feishu integration's allowlist implementation. The channels.feishu.allowFrom configuration is documented as an ID-based allowlist (accepting open_id values), but the actual policy matching incorrectly accepted mutable sender display names in the same namespace. An attacker could set a display name equal to an allowlisted ID string to pass authorization checks. The fix enforces ID-only matching, normalizes Feishu ID prefixes during comparison, and ignores mutable display names for authorization. The vulnerability affects openclaw up to and including version 2026.2.21-2, with a patch available in version 2026.2.22 and later.

Affected products

  • OpenClaw openclaw <= 2026.2.21-2

Timeline

  • 2026-03-03: disclosed: Advisory GHSA-j4xf-96qf-rx69 published
  • 2026-03-03: patched: Fix commit 4ed87a667263ed2d422b9d5d5a5d326e099f92c7 available; patched version 2026.2.22+ planned

References

Related threats