OpenClaw Feishu Auth Bypass
Fail-open authentication in AI agent messaging channel lets unauthenticated traffic reach command dispatch
CVE-2026-44109 / GHSA-xh72-v6v9-mwhc affects the openclaw npm package before version 2026.4.15. Two fail-open validation paths in the Feishu webhook integration allow unauthenticated inbound requests to bypass signature verification and reach OpenClaw's agent command dispatch. Missing encryptKey configuration is treated as acceptable rather than rejected at startup, and malformed card-action callbacks with blank tokens pass into lifecycle handling without rejection. OpenClaw connects LLM reasoning to shell execution, filesystem access, browser automation, Docker containers, and messaging platforms — making a channel-authentication bypass a direct path to those execution surfaces.
"Severity remains critical because affected webhook deployments expose a network-triggered path into OpenClaw command handling without the expected Feishu signature or replay protection."
— GitHub Advisory Database, GHSA-xh72-v6v9-mwhc
CVE Details
OpenClaw Feishu Webhook Fail-Open Authentication — Unauthenticated Command Dispatch
The openclaw npm package before 2026.4.15 contains two fail-open authentication defects in its Feishu integration. First, Feishu webhook mode accepts missing encryptKey configuration as valid rather than refusing to start. Second, malformed card-action callbacks with blank callback tokens pass into lifecycle handling without rejection. In affected deployments, an unauthenticated network request can bypass Feishu signature verification and replay-protection boundaries, reaching OpenClaw's agent command dispatch directly.
ROOT CAUSE
The root cause is a fail-open authentication design in two Feishu-related validation paths within the openclaw npm package. Feishu webhook mode treated a missing encryptKey configuration as acceptable rather than refusing startup or rejecting inbound requests. Separately, malformed card-action callbacks with blank callback tokens could be treated as usable lifecycle tokens rather than being dropped before handler dispatch. This maps to CWE-1188: Initialization of a Resource with an Insecure Default — the framework's Feishu integration was designed to require signature verification but defaulted to accepting requests when signing configuration was absent.
Attack Chain
Reconnaissance — Identify Exposed OpenClaw Feishu Webhook Endpoint
Attacker scans for OpenClaw deployments using Feishu webhook mode on versions before 2026.4.15. Webhook endpoints may be publicly exposed or reachable from adjacent network segments. OpenClaw is an agentic AI framework with broad execution access, making it a high-value target for reconnaissance.
Restrict webhook ingress to expected Feishu source IP ranges. Avoid exposing agent webhook endpoints to the public internet.
Initial Access — Send Unauthenticated Webhook or Card-Action Request
Attacker crafts a Feishu webhook event or card-action callback without a valid encryptKey signature. In vulnerable versions, missing encryptKey configuration is accepted as valid rather than rejected. No valid Feishu credentials or pre-existing access are required.
Upgrade to 2026.4.15 where webhook mode refuses to start without encryptKey and invalid signatures return 401.
Authentication Bypass — Fail-Open Validation Passes Unauthenticated Traffic
The vulnerable validation logic in extensions/feishu/src/monitor.transport.ts fails open instead of rejecting the request. Blank card-action callback tokens also pass into lifecycle handling without rejection. The request is treated as a legitimate authenticated event.
The patched version adds explicit rejection of missing encryptKey at startup and blank callback tokens before dispatch.
Command Dispatch — Unauthenticated Request Reaches OpenClaw Command Handling
The unauthenticated traffic reaches OpenClaw command dispatch, bypassing expected Feishu signature verification and replay-protection boundaries. In affected deployments this provides a network-triggered path into agent command handling with no prior authentication.
Segment channel adapters from command dispatch. Require explicit authentication, rate limiting, and audit logging at each boundary.
Execution Impact — Potential Access to AI Agent Execution Surfaces
OpenClaw connects LLM reasoning to shell execution, filesystem access, browser automation, Docker containers, and messaging platforms. A channel-authentication bypass may reach these execution surfaces depending on deployment configuration — giving an unauthenticated attacker the same execution capabilities as a legitimate user of the agent.
Apply minimal permissions, sandboxed execution, command allowlists, and human approval gates for destructive operations.
Impact
Agent Execution Surfaces
- Unauthenticated shell command execution
- Filesystem read and write access
- Docker container interaction
- Browser automation via agent tooling
Credential & Data Exposure
- Environment variable exfiltration
- API keys and secrets accessible to agent
- Messaging platform tokens and history
- LLM reasoning context and session data
Deployment Risk Factors
- Public internet exposure of webhook endpoint
- Missing encryptKey treated as valid configuration
- No replay protection on bypassed requests
- No detection signal for unauthenticated dispatch
Response Checklist
Patch all OpenClaw deployments to 2026.4.15 immediately. The fix enforces fail-closed behavior at startup — webhook mode refuses to initialize without a configured encryptKey, invalid signatures return 401, and blank card-action callback tokens are rejected before dispatch. Treat this as a same-day emergency update for any internet-accessible deployment.
Inventory every OpenClaw deployment using Feishu webhook mode and verify that encryptKey is set to a strong, unique value. Any deployment without a configured encryptKey running a pre-2026.4.15 version should be considered actively exploitable and taken offline until patched.
Audit ingress logs on all OpenClaw Feishu webhook endpoints for requests without valid signature headers or with blank callback tokens. Correlate anomalous requests with downstream agent activity — unexpected shell executions, filesystem reads, or external network calls following webhook events are indicators of exploitation.
If immediate upgrade to 2026.4.15 is not possible, disable Feishu webhook mode entirely until the patch can be applied. Do not attempt to mitigate the fail-open behavior through configuration alone on a vulnerable version — the defect is in the validation logic itself, not in configuration defaults.
Add automated tests that verify the webhook endpoint rejects requests with: a missing encryptKey, an invalid signature, and a blank card-action callback token. Negative-case testing — verifying that the system correctly rejects invalid inputs — is the primary control against fail-open regressions in future releases.
The channel adapter (Feishu webhook receiver) and the agent command dispatch layer should not share a trust boundary. An authentication failure in the channel adapter should not propagate into command handling. Enforce separation at the process or service boundary so that a bypassed channel adapter cannot directly invoke agent execution surfaces.
At the gateway or reverse proxy layer, restrict inbound traffic to the OpenClaw Feishu webhook endpoint to the published Feishu server IP ranges. Do not expose agent webhook endpoints to the public internet. Network-level ingress controls are a defense-in-depth layer, not a substitute for correct application-level authentication.
Configure alerting on 401 responses from the Feishu webhook endpoint after patching. A spike in signature validation failures is an indicator of active exploitation attempts. Correlate these alerts with downstream agent activity to detect any exploitation that may have occurred before the patch was applied.
Governance Framework
Channel Adapters as Control Planes
Treat AI agent channel adapters — Feishu, Slack, Teams, and similar integrations — as security-critical control planes with documented trust models. Every inbound channel event is an implicit instruction to the agent. The authentication layer is not optional infrastructure; it is the primary access control boundary.
Fail-Closed Startup Checks
Agent integrations must refuse to operate without required security configuration. Missing secrets, signing keys, or authentication credentials should cause a startup failure, not a degraded mode that accepts unauthenticated traffic. Fail-closed defaults are non-negotiable for any component that bridges external input to agent execution.
Layered Containment
Apply defense-in-depth across the agent execution stack: minimal permissions on host processes, sandboxed execution environments, command allowlists for destructive operations, and human approval gates for high-impact actions. A channel-authentication bypass should not grant unrestricted access to every capability the agent framework exposes.
Durable Audit Trails
Maintain audit logs that tie each inbound channel event to the downstream agent actions it triggers — including tool invocations, shell executions, and filesystem operations. Without this linkage, detecting exploitation after the fact is not possible. Audit trails must be write-once and stored outside the agent's own execution context.
Negative-Case Testing Culture
Fail-open defects survive because test suites verify that valid inputs are accepted, not that invalid inputs are rejected. Add negative-case tests for every authentication and validation boundary: missing credentials, malformed tokens, blank fields, and replayed requests. Security regressions in these paths are fail-open by default.
Network Isolation of Agent Endpoints
AI agent webhook endpoints that accept inbound control events should not be exposed to the public internet unless strictly necessary. Place them behind IP allowlists at the gateway layer, scoped to the published IP ranges of the channel provider. Treat lateral network reachability as an attack surface, not just external exposure.
References
[1] GitHub Security Advisory
GHSA-xh72-v6v9-mwhc — OpenClaw Feishu webhook authentication bypass. Disclosed April 16, 2026; patched in 2026.4.15.
[2] NVD
CVE-2026-44109 — openclaw npm package Feishu fail-open authentication, CVSS v4.0 9.2.
[3] VulnCheck
OpenClaw < 2026.4.15 Advisory — technical analysis of the fail-open initialization defect and affected validation paths in extensions/feishu/src/monitor.transport.ts.