PT-2026-99190 · Openclaw · Openclaw
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.6.9 through 2026.8.0
Description
The Feishu unpin feature fails to declare the native
chatId parameter as a delivery target. This allows unpin requests to bypass the shared same-provider cross-context target check. When the tools.message.crossContext.allowWithinProvider setting is disabled, an authenticated sender can remove a pin from a different Feishu group that both the sender and the configured account have permission to access. This bypasses the cross-context message mutation policy, although Feishu membership and group authorization remain in effect.Recommendations
Update OpenClaw to version 2026.8.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw