mediumVulnerability
GHSA-m69h-jm2f-2pv8
### Summary A Feishu reaction-originated synthetic event could misclassify a group conversation as `p2p` when the inbound reaction payload omitted `chat_type`. Authorization and mention-gating logic keyed off that incorrect chat type and evaluated the event as a direct message instead of a group message. ### Impact This could bypass `groupAllowFrom` and `requireMention` protections for reaction-derived events in Feishu group chats. ### Affected versions `openclaw` `<= 2026.3.11` ### Patch Fixed in `openclaw` `2026.3.12`. Reaction events now preserve the correct group context before authorization and mention-gate evaluation. Users should update to `2026.3.12` or later.
Properties
- ghsa_id
- GHSA-m69h-jm2f-2pv8
- severity
- medium
- summary
- OpenClaw: Feishu reaction events could bypass group authorization and mention gating
- cve_id
- GHSA-m69h-jm2f-2pv8
- is_ghsa_only
- true
- ghsa_published
- 2026-03-13T20:54:30Z
- source_url
- https://github.com/advisories/GHSA-m69h-jm2f-2pv8
- ghsa_updated
- 2026-03-13T20:54:31Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (2)
→[Weakness]Incorrect Authorization
→[Weakness]Improper Authorization
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph