{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/feishu--2026.6.9-beta.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["feishu (\u003c 2026.6.9-beta.1)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","software-vulnerability","supply-chain"],"_cs_type":"advisory","_cs_vendors":["OpenClaw"],"content_html":"\u003cp\u003eThe OpenClaw feishu package (version \u0026lt; 2026.6.9-beta.1) contains an authorization bypass vulnerability that causes the software to ignore per-account disablement configurations. This defect permits a lower-trust caller or a reachable input path to execute operations that should have been restricted by the intended authorization or security policy. Because the Feishu module interacts with external messaging and collaboration services, this flaw poses a significant risk to organizations where Gateway operators may be exposed to untrusted inputs or where service accounts share gateways across different trust boundaries. This vulnerability does not impact the core trusted-operator model of OpenClaw itself, but rather specifically affects the enforcement of access controls within the Feishu integration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe failure to enforce per-account disablement policies may allow unauthorized actions within the Feishu environment, potentially leading to unauthorized data access, message manipulation, or unintended API interactions. The extent of the damage is dependent on the specific configuration of the OpenClaw Gateway and the ability of attackers to route malicious or unauthorized input through the affected Feishu tools.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the OpenClaw @openclaw/feishu package to version 2026.6.9 or later immediately.\u003c/li\u003e\n\u003cli\u003eDisable the affected Feishu feature within the OpenClaw configuration if it is not explicitly required for business operations.\u003c/li\u003e\n\u003cli\u003eReview and restrict channel and tool allowlists for the Gateway to limit the impact of potential unauthorized command execution.\u003c/li\u003e\n\u003cli\u003eEnsure that separate OpenClaw Gateways are used for mutually untrusted user groups to maintain appropriate isolation boundaries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T18:04:24Z","date_published":"2026-09-03T18:04:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-feishu-auth-bypass/","summary":"The OpenClaw feishu package is susceptible to an authorization bypass vulnerability where per-account disablement settings are ignored, potentially allowing lower-trust entities to execute unauthorized actions.","title":"Authorization Bypass in OpenClaw Feishu Package","url":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-feishu-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Feishu (\u003c 2026.6.9-Beta.1)","version":"https://jsonfeed.org/version/1.1"}