Executive brief
OpenClaw, a gateway and plugin platform, contains a flaw in how it handles Feishu dynamic-agent bindings. An attacker could potentially create or update these bindings even when the system is configured to prevent such changes. This could allow unauthorized modifications to how messages or tasks are routed within the platform, depending on the specific environment configuration.
Technical details
A missing authorization vulnerability (CWE-862) exists in OpenClaw's Feishu dynamic-agent binding behavior. In affected versions, the system fails to properly enforce 'configWrites' controls, allowing a Feishu sender to create or update agent bindings regardless of the intended policy. The attack requires network reachability and low privileges, with high complexity due to specific configuration requirements. The issue is addressed in version 2026.5.6; users can mitigate the risk by disabling sender-created Feishu dynamic-agent bindings.
Affected products
- openclaw openclaw <= 2026.5.5
Timeline
- 2026-05-28: disclosed
- 2026-07-02: advisory
- 2026-05-28: patched: First stable patched version is 2026.5.6