CVE-2026-100553
Received Received - Intake

Path Traversal in OpenClaw Feishu Extension

Vulnerability report for CVE-2026-100553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is disabled, an admitted (authenticated) sender can remove a pin from another Feishu group that the sender and the configured account are otherwise permitted to access, bypassing the intended cross-context message mutation policy. Feishu membership and group authorization still apply, and the demonstrated impact is limited to message mutation (pin removal). The issue is fixed in 2026.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openclaw openclaw From 2026.6.9 (inc) to 2026.8.1 (exc)
feishu feishu to 2026.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OpenClaw versions between 2026.6.9 and 2026.8.1. It involves a cross-context policy bypass in the Feishu unpin feature where the native chatId parameter is not declared as a delivery target. This allows authenticated senders to remove pins from Feishu groups they have access to, even when cross-context message mutation policies are enforced, but only if the tools.message.crossContext.allowWithinProvider setting is disabled.

Detection Guidance

Check OpenClaw version to see if it falls within the vulnerable range (>=2026.6.9 and <2026.8.1). Review Feishu group pin management logs for unauthorized pin removal actions by authenticated users. Inspect configuration for tools.message.crossContext.allowWithinProvider setting to confirm if it is disabled.

Impact Analysis

An admitted sender could remove a pin from another Feishu group they are permitted to access. The impact is limited to message mutation, specifically pin removal, while membership and group authorization remain intact. Feishu policies still apply, so the effect is constrained to unauthorized pin removal within allowed groups.

Compliance Impact

This vulnerability allows limited message mutation (pin removal) in Feishu groups by authenticated users, but does not directly impact data confidentiality or integrity beyond that scope. It does not appear to violate GDPR or HIPAA requirements as it does not expose or alter protected health or personal data beyond permitted group access.

Mitigation Strategies

Upgrade OpenClaw to version 2026.8.1 or later. If upgrading is not immediately possible, disable Feishu pin-management actions for lower-trust senders as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart