Critical · CVSS 9.2 April 16, 2026 · VulnCheck / GitHub Advisory Database

OpenClaw Feishu Auth Bypass

Fail-open authentication in AI agent messaging channel lets unauthenticated traffic reach command dispatch

CVE-2026-44109 / GHSA-xh72-v6v9-mwhc affects the openclaw npm package before version 2026.4.15. Two fail-open validation paths in the Feishu webhook integration allow unauthenticated inbound requests to bypass signature verification and reach OpenClaw's agent command dispatch. Missing encryptKey configuration is treated as acceptable rather than rejected at startup, and malformed card-action callbacks with blank tokens pass into lifecycle handling without rejection. OpenClaw connects LLM reasoning to shell execution, filesystem access, browser automation, Docker containers, and messaging platforms — making a channel-authentication bypass a direct path to those execution surfaces.

1 CVE
9.2 CVSS v4.0
Auth Bypass Class
2026.4.15 Fixed In

"Severity remains critical because affected webhook deployments expose a network-triggered path into OpenClaw command handling without the expected Feishu signature or replay protection."

— GitHub Advisory Database, GHSA-xh72-v6v9-mwhc

CVE Details

CVE-2026-44109 Critical · 9.2 Authentication Bypass

OpenClaw Feishu Webhook Fail-Open Authentication — Unauthenticated Command Dispatch

The openclaw npm package before 2026.4.15 contains two fail-open authentication defects in its Feishu integration. First, Feishu webhook mode accepts missing encryptKey configuration as valid rather than refusing to start. Second, malformed card-action callbacks with blank callback tokens pass into lifecycle handling without rejection. In affected deployments, an unauthenticated network request can bypass Feishu signature verification and replay-protection boundaries, reaching OpenClaw's agent command dispatch directly.

Affected: openclaw / OpenClaw npm, versions before 2026.4.15  ·  GHSA: GHSA-xh72-v6v9-mwhc  ·  CWE: CWE-1188 (Insecure Default Initialization)  ·  Impact: Unauthenticated network-triggered access to AI agent command dispatch and downstream execution surfaces.

ROOT CAUSE

The root cause is a fail-open authentication design in two Feishu-related validation paths within the openclaw npm package. Feishu webhook mode treated a missing encryptKey configuration as acceptable rather than refusing startup or rejecting inbound requests. Separately, malformed card-action callbacks with blank callback tokens could be treated as usable lifecycle tokens rather than being dropped before handler dispatch. This maps to CWE-1188: Initialization of a Resource with an Insecure Default — the framework's Feishu integration was designed to require signature verification but defaulted to accepting requests when signing configuration was absent.

Validation Path Expected Vulnerable Patched
Webhook signing config Refuse without encryptKey Missing key accepted as valid Refuses to start without encryptKey
Signature validation Reject invalid signatures → 401 Could fail open Invalid signatures return 401
Card-action callback token Reject blank tokens before dispatch Blank tokens could pass Blank tokens rejected before dispatch
Command dispatch boundary Only authenticated events reach dispatch Unauthenticated traffic may reach dispatch Validation fails closed

Attack Chain

1

Reconnaissance — Identify Exposed OpenClaw Feishu Webhook Endpoint

Attacker scans for OpenClaw deployments using Feishu webhook mode on versions before 2026.4.15. Webhook endpoints may be publicly exposed or reachable from adjacent network segments. OpenClaw is an agentic AI framework with broad execution access, making it a high-value target for reconnaissance.

Restrict webhook ingress to expected Feishu source IP ranges. Avoid exposing agent webhook endpoints to the public internet.

2

Initial Access — Send Unauthenticated Webhook or Card-Action Request

Attacker crafts a Feishu webhook event or card-action callback without a valid encryptKey signature. In vulnerable versions, missing encryptKey configuration is accepted as valid rather than rejected. No valid Feishu credentials or pre-existing access are required.

Upgrade to 2026.4.15 where webhook mode refuses to start without encryptKey and invalid signatures return 401.

3

Authentication Bypass — Fail-Open Validation Passes Unauthenticated Traffic

The vulnerable validation logic in extensions/feishu/src/monitor.transport.ts fails open instead of rejecting the request. Blank card-action callback tokens also pass into lifecycle handling without rejection. The request is treated as a legitimate authenticated event.

The patched version adds explicit rejection of missing encryptKey at startup and blank callback tokens before dispatch.

4

Command Dispatch — Unauthenticated Request Reaches OpenClaw Command Handling

The unauthenticated traffic reaches OpenClaw command dispatch, bypassing expected Feishu signature verification and replay-protection boundaries. In affected deployments this provides a network-triggered path into agent command handling with no prior authentication.

Segment channel adapters from command dispatch. Require explicit authentication, rate limiting, and audit logging at each boundary.

5

Execution Impact — Potential Access to AI Agent Execution Surfaces

OpenClaw connects LLM reasoning to shell execution, filesystem access, browser automation, Docker containers, and messaging platforms. A channel-authentication bypass may reach these execution surfaces depending on deployment configuration — giving an unauthenticated attacker the same execution capabilities as a legitimate user of the agent.

Apply minimal permissions, sandboxed execution, command allowlists, and human approval gates for destructive operations.

Impact

Agent Execution Surfaces

  • Unauthenticated shell command execution
  • Filesystem read and write access
  • Docker container interaction
  • Browser automation via agent tooling

Credential & Data Exposure

  • Environment variable exfiltration
  • API keys and secrets accessible to agent
  • Messaging platform tokens and history
  • LLM reasoning context and session data

Deployment Risk Factors

  • Public internet exposure of webhook endpoint
  • Missing encryptKey treated as valid configuration
  • No replay protection on bypassed requests
  • No detection signal for unauthenticated dispatch

Response Checklist

STEP 01 Upgrade OpenClaw to Version 2026.4.15 or Later Immediate

Patch all OpenClaw deployments to 2026.4.15 immediately. The fix enforces fail-closed behavior at startup — webhook mode refuses to initialize without a configured encryptKey, invalid signatures return 401, and blank card-action callback tokens are rejected before dispatch. Treat this as a same-day emergency update for any internet-accessible deployment.

STEP 02 Audit All Feishu Webhook Deployments for a Configured encryptKey Immediate

Inventory every OpenClaw deployment using Feishu webhook mode and verify that encryptKey is set to a strong, unique value. Any deployment without a configured encryptKey running a pre-2026.4.15 version should be considered actively exploitable and taken offline until patched.

STEP 03 Review Ingress Logs for Unauthenticated Webhook and Card-Action Requests Immediate

Audit ingress logs on all OpenClaw Feishu webhook endpoints for requests without valid signature headers or with blank callback tokens. Correlate anomalous requests with downstream agent activity — unexpected shell executions, filesystem reads, or external network calls following webhook events are indicators of exploitation.

STEP 04 Temporarily Disable Feishu Webhook Mode if Patching Is Not Possible Immediate

If immediate upgrade to 2026.4.15 is not possible, disable Feishu webhook mode entirely until the patch can be applied. Do not attempt to mitigate the fail-open behavior through configuration alone on a vulnerable version — the defect is in the validation logic itself, not in configuration defaults.

STEP 05 Add Negative-Case Tests for Authentication Failure Scenarios Urgent

Add automated tests that verify the webhook endpoint rejects requests with: a missing encryptKey, an invalid signature, and a blank card-action callback token. Negative-case testing — verifying that the system correctly rejects invalid inputs — is the primary control against fail-open regressions in future releases.

STEP 06 Segment Feishu Channel Adapters from Privileged Execution Components Urgent

The channel adapter (Feishu webhook receiver) and the agent command dispatch layer should not share a trust boundary. An authentication failure in the channel adapter should not propagate into command handling. Enforce separation at the process or service boundary so that a bypassed channel adapter cannot directly invoke agent execution surfaces.

STEP 07 Restrict Feishu Webhook Ingress to Expected Source IP Ranges Urgent

At the gateway or reverse proxy layer, restrict inbound traffic to the OpenClaw Feishu webhook endpoint to the published Feishu server IP ranges. Do not expose agent webhook endpoints to the public internet. Network-level ingress controls are a defense-in-depth layer, not a substitute for correct application-level authentication.

STEP 08 Enable Alerting on Requests That Fail Feishu Signature Validation Urgent

Configure alerting on 401 responses from the Feishu webhook endpoint after patching. A spike in signature validation failures is an indicator of active exploitation attempts. Correlate these alerts with downstream agent activity to detect any exploitation that may have occurred before the patch was applied.

Governance Framework

Channel Adapters as Control Planes

Treat AI agent channel adapters — Feishu, Slack, Teams, and similar integrations — as security-critical control planes with documented trust models. Every inbound channel event is an implicit instruction to the agent. The authentication layer is not optional infrastructure; it is the primary access control boundary.

Fail-Closed Startup Checks

Agent integrations must refuse to operate without required security configuration. Missing secrets, signing keys, or authentication credentials should cause a startup failure, not a degraded mode that accepts unauthenticated traffic. Fail-closed defaults are non-negotiable for any component that bridges external input to agent execution.

Layered Containment

Apply defense-in-depth across the agent execution stack: minimal permissions on host processes, sandboxed execution environments, command allowlists for destructive operations, and human approval gates for high-impact actions. A channel-authentication bypass should not grant unrestricted access to every capability the agent framework exposes.

Durable Audit Trails

Maintain audit logs that tie each inbound channel event to the downstream agent actions it triggers — including tool invocations, shell executions, and filesystem operations. Without this linkage, detecting exploitation after the fact is not possible. Audit trails must be write-once and stored outside the agent's own execution context.

Negative-Case Testing Culture

Fail-open defects survive because test suites verify that valid inputs are accepted, not that invalid inputs are rejected. Add negative-case tests for every authentication and validation boundary: missing credentials, malformed tokens, blank fields, and replayed requests. Security regressions in these paths are fail-open by default.

Network Isolation of Agent Endpoints

AI agent webhook endpoints that accept inbound control events should not be exposed to the public internet unless strictly necessary. Place them behind IP allowlists at the gateway layer, scoped to the published IP ranges of the channel provider. Treat lateral network reachability as an attack surface, not just external exposure.

References

[1] GitHub Security Advisory

GHSA-xh72-v6v9-mwhc — OpenClaw Feishu webhook authentication bypass. Disclosed April 16, 2026; patched in 2026.4.15.

[2] NVD

CVE-2026-44109 — openclaw npm package Feishu fail-open authentication, CVSS v4.0 9.2.

[3] VulnCheck

OpenClaw < 2026.4.15 Advisory — technical analysis of the fail-open initialization defect and affected validation paths in extensions/feishu/src/monitor.transport.ts.

Primary sources: GitHub Advisory Database (GHSA-xh72-v6v9-mwhc), NVD (CVE-2026-44109), VulnCheck. Disclosed April 16, 2026; patched in openclaw 2026.4.15. This advisory is an independent defensive guide produced by Spectreworks AI for educational purposes only.