rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3 · EPSS 0.00215

CVE-2026-100553

OpenClaw versions 2026.6.9 through 2026.8.0 allow an authenticated user to unpin a message in another Feishu group by bypassing the cross‑co

Overview

OpenClaw versions 2026.6.9 through 2026.8.0 allow an authenticated user to unpin a message in another Feishu group by bypassing the cross‑context target check. The flaw is limited to message mutation and does not affect group membership or message content. It is fixed in OpenClaw 2026.8.1.

Description

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is disabled, an admitted (authenticated) sender can remove a pin from another Feishu group that the sender and the configured account are otherwise permitted to access, bypassing the intended cross-context message mutation policy. Feishu membership and group authorization still apply, and the demonstrated impact is limited to message mutation (pin removal). The issue is fixed in 2026.8.1.

Impact

Confidentiality is not affected. Integrity is impacted because an authorized user can remove a pin from a group they normally cannot modify, potentially disrupting group communication. Availability is not affected. Defenders should monitor unpin activity and enforce least‑privilege policies for group management.

Remediation

Apply the OpenClaw 2026.8.1 patch or later. Until the patch is applied, enable the tools.message.crossContext.allowWithinProvider setting to prevent cross‑context unpin operations, or restrict unpin permissions to trusted users only.

Risk context

The vulnerability has a medium severity (CVSS v3 4.3, v4 5.3) and a very low EPSS score of 0.00215, indicating a low likelihood of exploitation but still requiring timely patching.

Affected products

  • OpenClaw
  • Feishu

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
5.3
EPSS
0.00215

Feishu OpenClaw message-mutation cross-context medium-severity EPSS-low patch-required

← All CVEs