<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Feishu (&lt; 2026.6.9-Beta.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/feishu--2026.6.9-beta.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 18:04:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/feishu--2026.6.9-beta.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in OpenClaw Feishu Package</title><link>https://feed.craftedsignal.io/briefs/2026-09-openclaw-feishu-auth-bypass/</link><pubDate>Thu, 03 Sep 2026 18:04:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openclaw-feishu-auth-bypass/</guid><description>The OpenClaw feishu package is susceptible to an authorization bypass vulnerability where per-account disablement settings are ignored, potentially allowing lower-trust entities to execute unauthorized actions.</description><content:encoded><![CDATA[<p>The OpenClaw feishu package (version &lt; 2026.6.9-beta.1) contains an authorization bypass vulnerability that causes the software to ignore per-account disablement configurations. This defect permits a lower-trust caller or a reachable input path to execute operations that should have been restricted by the intended authorization or security policy. Because the Feishu module interacts with external messaging and collaboration services, this flaw poses a significant risk to organizations where Gateway operators may be exposed to untrusted inputs or where service accounts share gateways across different trust boundaries. This vulnerability does not impact the core trusted-operator model of OpenClaw itself, but rather specifically affects the enforcement of access controls within the Feishu integration.</p>
<h2 id="impact">Impact</h2>
<p>The failure to enforce per-account disablement policies may allow unauthorized actions within the Feishu environment, potentially leading to unauthorized data access, message manipulation, or unintended API interactions. The extent of the damage is dependent on the specific configuration of the OpenClaw Gateway and the ability of attackers to route malicious or unauthorized input through the affected Feishu tools.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the OpenClaw @openclaw/feishu package to version 2026.6.9 or later immediately.</li>
<li>Disable the affected Feishu feature within the OpenClaw configuration if it is not explicitly required for business operations.</li>
<li>Review and restrict channel and tool allowlists for the Gateway to limit the impact of potential unauthorized command execution.</li>
<li>Ensure that separate OpenClaw Gateways are used for mutually untrusted user groups to maintain appropriate isolation boundaries.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>software-vulnerability</category><category>supply-chain</category></item></channel></rss>