Improper access control in OpenClaw - #VU126839
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass dmPolicy restrictions for card-action flows.
The vulnerability exists due to improper access control in Feishu card-action handling when synthesizing and dispatching message events for direct-message conversations. A remote user can trigger a crafted card-action flow from a Feishu direct message to bypass dmPolicy restrictions for card-action flows.
The issue is limited to Feishu card-action handling.