Improper access control in OpenClaw - #VU125252

 

Improper access control in OpenClaw - #VU125252

Published: April 8, 2026


Vulnerability identifier: #VU125252
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass sender allowlist restrictions.

The vulnerability exists due to improper access control in Feishu thread history and quoted message context handling when fetching quoted, root, or thread context. A remote attacker can send messages that cause disallowed sender content to be included to bypass sender allowlist restrictions.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.3.31

External References

Related Security Bulletins