Executive brief
OpenClaw, a library for interacting with the Feishu platform, contains a vulnerability where certain message card types can bypass security pairing requirements. This allows unauthorized recipients to trigger callback actions that should normally be restricted to paired direct messages. An attacker could exploit this to interact with automated workflows or data handling processes without the proper authorization.
Technical details
A vulnerability in OpenClaw (versions <= 2026.3.24) allows the creation of legacy Feishu raw card callback payloads that bypass Direct Message (DM) pairing requirements. This issue stems from the 'Raw Card Send Surface' incorrectly minting legacy callback structures that do not enforce the standard paired path for callback handling. An attacker can use these legacy payloads to reach callback handlers from unpaired recipients, leading to an authentication bypass (CWE-288) or incorrect authorization (CWE-863). The issue was addressed in version 2026.3.25 (and later 2026.3.28) by rejecting legacy raw-card command payloads to ensure all callbacks follow the validated paired path.
Affected products
- openclaw openclaw <= 2026.3.24
Timeline
- 2026-03-26: disclosed: Vulnerability reported and initial patch activity.
- 2026-03-29: advisory: GitHub Advisory GHSA-77w2-crqv-cmv3 published.
- 2026-03-25: patched: First patched version 2026.3.25 released.