Executive brief
OpenClaw is an automation and command execution platform that integrates with Feishu (a team messaging service) via webhooks and card-action callbacks. The vulnerability allows unauthenticated attackers on the network to send malicious webhook or callback requests directly to command dispatch, bypassing signature verification and replay protection. This could enable unauthorized command execution and system compromise without proper authentication.
Technical details
The vulnerability is an authentication bypass affecting Feishu webhook and card-action validation in OpenClaw. Two fail-open conditions allow requests to bypass security checks: (1) webhook mode accepts missing encryptKey configuration as valid instead of rejecting startup, and (2) card-action callbacks with blank tokens are treated as usable instead of being rejected before dispatch. The vulnerability requires network access to the webhook endpoint but no prior authentication or user interaction. An attacker can send unauthenticated or replayed requests directly to command handling without valid Feishu signatures or replay tokens. The fix in version 2026.4.15 enforces fail-closed validation: refusing webhook startup without encryptKey, returning 401 for invalid signatures, and rejecting blank callback tokens at the lifecycle guard.
Affected products
- OpenClaw OpenClaw < 2026.4.15
Timeline
- 2026-04-17: disclosed
- 2026-04-15: patched: Version 2026.4.15 released