PT-2026-27295 · Npm · Openclaw
Publicado
2026-03-13
·
Atualizado
2026-03-13
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Summary
A Feishu reaction-originated synthetic event could misclassify a group conversation as
p2p when the inbound reaction payload omitted chat type. Authorization and mention-gating logic keyed off that incorrect chat type and evaluated the event as a direct message instead of a group message.Impact
This could bypass
groupAllowFrom and requireMention protections for reaction-derived events in Feishu group chats.Affected versions
openclaw <= 2026.3.11Patch
Fixed in
openclaw 2026.3.12. Reaction events now preserve the correct group context before authorization and mention-gate evaluation. Users should update to 2026.3.12 or later.Correção
Improper Authorization
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw