mediumVulnerability

GHSA-72q8-jcmc-97wx

## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `< 2026.4.20` - Patched version: `2026.4.20` ## Impact Feishu card-action callbacks could synthesize a message event with DM conversations classified as group conversations. That skipped `dmPolicy` enforcement for card actions, so a sender in a Feishu DM could trigger card-action flows that should have been blocked by a restrictive DM policy. The issue is limited to Feishu card-action handling. Severity is medium. ## Fix OpenClaw now resolves Feishu card-action chat type before dispatch, including API lookup when stored context is unavailable, and avoids falling through to group handling for DMs. Fix commit: - `90979d7c3ef7ec30b9f8aa6963a5e38d2f17d166` ## Release Fixed in OpenClaw `2026.4.20`.

Properties

ghsa_id
GHSA-72q8-jcmc-97wx
severity
medium
summary
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
cve_id
GHSA-72q8-jcmc-97wx
is_ghsa_only
true
ghsa_published
2026-04-25T23:46:31Z
source_url
https://github.com/advisories/GHSA-72q8-jcmc-97wx
ghsa_updated
2026-04-25T23:46:31Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/OpenClaw

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph