Agents
Two OpenClaw advisories: Feishu tools ignored per-account disablement
GHSA-w8wf-3qvj-6xqf and GHSA-2q7j-2vhx-56g8, both high and published 2026-09-03, cover the @openclaw/feishu package, where permission tools and general Feishu tools could ignore per-account disablement so a lower-trust caller or configured input path performed actions that should have required a stronger authorization check. The first stable patched version is 2026.6.9. The advisories are explicit that they do not change OpenClaw's trusted-operator model, and the interim mitigation is to keep channel and tool allowlists narrow and avoid sharing one Gateway between mutually untrusted users.
↳ Follow the thread