Improper access control in OpenClaw - #VU125252

 

Improper access control in OpenClaw - #VU125252

Published: April 8, 2026


Vulnerability identifier: #VU125252
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: OpenClaw
Affected software:
OpenClaw

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass sender allowlist restrictions.

The vulnerability exists due to improper access control in Feishu thread history and quoted message context handling when fetching quoted, root, or thread context. A remote attacker can send messages that cause disallowed sender content to be included to bypass sender allowlist restrictions.


Remediation

Install security update from vendor's website.

Sources