VYPR

feishu

by OpenClaw

CVEs (2)

  • CVE-2026-100540MedSep 26, 2026
    risk 0.37cvss 6.8epss —

    OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources…

  • CVE-2026-100582MedSep 26, 2026
    risk 0.35cvss 6.5epss —

    OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read…