Executive brief
OpenClaw's Feishu integration tools are used to connect to the Feishu collaboration platform within the OpenClaw workflow automation gateway. A flaw in per-account access controls allows lower-trust callers to bypass authorization checks and perform actions that should have been restricted, potentially leading to unauthorized data access or modification depending on the operator's configuration.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in the Feishu tools component of OpenClaw that could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller through a configured input path could bypass authorization checks and perform actions that should require stronger privilege levels. The attack requires network access and low-level privileges but no user interaction. The vulnerability affects versions prior to 2026.6.9-beta.1, with the first stable patched version being 2026.6.9. This scoped vulnerability does not affect OpenClaw's trusted-operator model for authenticated Gateway operators and installed plugins.
Affected products
- OpenClaw @openclaw/feishu < 2026.6.9-beta.1
Timeline
- 2026-06-30: disclosed
- 2026-09-03: advisory
- 2026-06-30: patched: Beta patch version 2026.6.9-beta.1 released; first stable patched version 2026.6.9