Message Classification Vulnerability in OpenClaw Affects Direct Messaging Features
CVE-2026-44993
2.3LOW
What is CVE-2026-44993?
OpenClaw versions prior to 2026.4.20 are vulnerable to a message classification flaw within Feishu card-action callbacks. This vulnerability allows attackers to wrongly classify direct messages as group conversations, enabling them to bypass dmPolicy enforcement. As a result, attackers can exploit card-action triggers in direct message conversations that would typically be restricted, compromising user privacy and security measures in place.
Affected Version(s)
OpenClaw 0 < 2026.4.20
OpenClaw 2026.4.20
