Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-xh72-v6v9-mwhc
No affected components available
Summary
Feishu webhook mode accepted missing encryptKey configuration as valid and blank card-action callback tokens as usable lifecycle tokens. Together, those fail-open paths could allow unauthenticated webhook or card-action traffic to reach command dispatch in affected deployments.
Impact
A deployment using Feishu webhook mode without a configured encryptKey, or handling malformed card-action callbacks with blank callback tokens, could fail open instead of rejecting the request. Severity remains critical because affected webhook deployments expose a network-triggered path into OpenClaw command handling without the expected Feishu signature or replay protection.
Affected versions
- Affected:
< 2026.4.15 - Patched:
2026.4.15
Fix
OpenClaw 2026.4.15 makes Feishu webhook and card-action validation fail closed. Webhook mode now refuses to start without an encryptKey, missing signing configuration returns invalid instead of valid, invalid signatures return 401, and blank card-action callback tokens are rejected before dispatch.
Verified in v2026.4.15:
extensions/feishu/src/monitor.transport.tsreturns invalid whenencryptKeyis missing, refuses webhook mode withoutencryptKey, and rejects invalid signatures before JSON handling.extensions/feishu/src/card-action.tsrejects blank callback tokens in the card-action lifecycle guard.extensions/feishu/src/monitor.webhook-security.test.tscovers missing-encryptKeystartup and transport rejection.extensions/feishu/src/monitor.card-action.lifecycle.test.tscovers malformed blank-token card actions being dropped before handler dispatch.
Fix commit included in v2026.4.15 and absent from v2026.4.14:
c8003f1b33ed2924be5f62131bd28742c5a41aaevia PR #66707
Thanks to @dhyabi2 for reporting this issue.
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.
Active exploitation in the wild has been confirmed. Immediate patching or mitigation is required.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard