GHSA-72q8-jcmc-97wx
## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `< 2026.4.20` - Patched version: `2026.4.20` ## Impact Feishu card-action callbacks could synthesize a message event with DM conversations classified as group conversations. That skipped `dmPolicy` enforcement for card actions, so a sender in a Feishu DM could trigger card-action flows that should have been blocked by a restrictive DM policy. The issue is limited to Feishu card-action handling. Severity is medium. ## Fix OpenClaw now resolves Feishu card-action chat type before dispatch, including API lookup when stored context is unavailable, and avoids falling through to group handling for DMs. Fix commit: - `90979d7c3ef7ec30b9f8aa6963a5e38d2f17d166` ## Release Fixed in OpenClaw `2026.4.20`.
Properties
- ghsa_id
- GHSA-72q8-jcmc-97wx
- severity
- medium
- summary
- OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
- cve_id
- GHSA-72q8-jcmc-97wx
- is_ghsa_only
- true
- ghsa_published
- 2026-04-25T23:46:31Z
- source_url
- https://github.com/advisories/GHSA-72q8-jcmc-97wx
- ghsa_updated
- 2026-04-25T23:46:31Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph