Cross-Context Policy Bypass in OpenClaw by Feishu Unpin Feature
CVE-2026-100553
5.3MEDIUM
What is CVE-2026-100553?
OpenClaw's Feishu unpin feature has a vulnerability in versions 2026.6.9 to 2026.8.1 where the native chatId parameter is not adequately declared as a delivery target. This oversight allows authenticated users to bypass the intended cross-context message mutation policy, enabling them to remove pins from Feishu groups they have access to. Although group authorization is still enforced, this flaw poses a risk of unintended message mutations within shared contexts. The vulnerability has been resolved in version 2026.8.1.
Affected Version(s)
OpenClaw 2026.6.9 < 2026.8.1
OpenClaw 2026.8.1
