Executive brief
OpenClaw's Feishu integration, a tool used for managing permissions and communications within the Feishu platform, contains a security flaw where it may ignore specific account-level restrictions. This allows users with low-level access to bypass intended security policies and perform actions they should not be authorized to do. If exploited, this could lead to unauthorized data access or modification within the Feishu environment.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the @openclaw/feishu package for OpenClaw. The root cause is a failure in the Feishu permission tools to respect per-account disablement settings, effectively bypassing intended policy checks. An authenticated attacker with low privileges can exploit this over the network to perform actions that should require higher authorization levels. This can result in a significant loss of confidentiality and integrity if lower-trust input paths reach the affected feature. The vulnerability is addressed in version 2026.6.9.
Affected products
- OpenClaw feishu (@openclaw/feishu) <= 2026.6.6
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-13: disclosed: NVD publication date
- 2026-07-13: patched: Fix confirmed in version 2026.6.9