PT-2026-37321 · Npm · Openclaw

Published

2026-04-25

·

Updated

2026-04-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: < 2026.4.20
  • Patched version: 2026.4.20

Impact

Feishu card-action callbacks could synthesize a message event with DM conversations classified as group conversations. That skipped dmPolicy enforcement for card actions, so a sender in a Feishu DM could trigger card-action flows that should have been blocked by a restrictive DM policy.
The issue is limited to Feishu card-action handling. Severity is medium.

Fix

OpenClaw now resolves Feishu card-action chat type before dispatch, including API lookup when stored context is unavailable, and avoids falling through to group handling for DMs.
Fix commit:
  • 90979d7c3ef7ec30b9f8aa6963a5e38d2f17d166

Release

Fixed in OpenClaw 2026.4.20.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-72Q8-JCMC-97WX

Affected Products

Openclaw