Junglewise Threat Intelligence

CVE-2026-44993: OpenClaw policy bypass via Feishu message misclassification

CVE-2026-44993 · Severity: medium · CVSS 5.4 · Published 2026-05-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an open-source integration tool, contains a flaw in how it handles Feishu (Lark) messaging platform interactions. Specifically, the system can mistake private direct messages for group conversations, allowing users to bypass security policies intended to restrict certain actions in private chats. This could lead to unauthorized execution of automated workflows or data interactions that should have been blocked by administrative settings.

Technical details

A message classification vulnerability exists in OpenClaw's Feishu card-action callback handler. Due to improper validation of chat types (preferring chat_type over chat_mode or failing to resolve context), direct message (DM) conversations can be misidentified as group conversations. This logic error allows an attacker to bypass 'dmPolicy' enforcement by triggering card-action flows in DM conversations that should have been restricted. The vulnerability is rooted in the normalizer's failure to correctly map Feishu's 'private' or 'public' chat_type fields to the appropriate internal conversation semantics. A fix was introduced in version 2026.4.20 which ensures chat type resolution via the Feishu API when stored context is missing.

Affected products

  • OpenClaw openclaw < 2026.4.20

Timeline

  • 2026-04-17: patched: Fix commit 90979d7c3ef7ec30b9f8aa6963a5e38d2f17d166 merged
  • 2026-04-21: advisory: GitHub Security Advisory GHSA-72q8-jcmc-97wx published
  • 2026-05-11: disclosed: CVE-2026-44993 published to NVD

References

Related threats