Improper access control in OpenClaw - #VU125252
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass sender allowlist restrictions.
The vulnerability exists due to improper access control in Feishu thread history and quoted message context handling when fetching quoted, root, or thread context. A remote attacker can send messages that cause disallowed sender content to be included to bypass sender allowlist restrictions.