VYPR

Openclaw\/feishu

by OpenClaw

CVEs (2)

  • CVE-2026-62188HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured…

  • CVE-2026-62187HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized…