UNKNOWN npm

OpenClaw: Feishu reaction events could bypass group authorization and mention gating

GHSA-m69h-jm2f-2pv8 · CVE-2026-32924

Published · Modified

Description

Summary

A Feishu reaction-originated synthetic event could misclassify a group conversation as p2p when the inbound reaction payload omitted chat_type. Authorization and mention-gating logic keyed off that incorrect chat type and evaluated the event as a direct message instead of a group message.

Impact

This could bypass groupAllowFrom and requireMention protections for reaction-derived events in Feishu group chats.

Affected versions

openclaw <= 2026.3.11

Patch

Fixed in openclaw 2026.3.12. Reaction events now preserve the correct group context before authorization and mention-gate evaluation. Users should update to 2026.3.12 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes