mediumVulnerability

GHSA-m69h-jm2f-2pv8

### Summary A Feishu reaction-originated synthetic event could misclassify a group conversation as `p2p` when the inbound reaction payload omitted `chat_type`. Authorization and mention-gating logic keyed off that incorrect chat type and evaluated the event as a direct message instead of a group message. ### Impact This could bypass `groupAllowFrom` and `requireMention` protections for reaction-derived events in Feishu group chats. ### Affected versions `openclaw` `<= 2026.3.11` ### Patch Fixed in `openclaw` `2026.3.12`. Reaction events now preserve the correct group context before authorization and mention-gate evaluation. Users should update to `2026.3.12` or later.

Properties

ghsa_id
GHSA-m69h-jm2f-2pv8
severity
medium
summary
OpenClaw: Feishu reaction events could bypass group authorization and mention gating
cve_id
GHSA-m69h-jm2f-2pv8
is_ghsa_only
true
ghsa_published
2026-03-13T20:54:30Z
source_url
https://github.com/advisories/GHSA-m69h-jm2f-2pv8
ghsa_updated
2026-03-13T20:54:31Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Incorrect Authorization
[Weakness]Improper Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph