OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
Moderate severity
GitHub Reviewed
Published
Mar 26, 2026
in
openclaw/openclaw
•
Updated Mar 29, 2026
Description
Published to the GitHub Advisory Database
Mar 29, 2026
Reviewed
Mar 29, 2026
Last updated
Mar 29, 2026
Summary
Feishu webhook reads and parses unauthenticated request bodies before signature validation
Affected Packages / Versions
openclaw<= 2026.3.242026.3.252026.3.24Details
Feishu webhook handling previously parsed JSON before signature validation, which let unauthenticated callers force full JSON parsing work before rejection. Commit
5e8cb22176e9235e224be0bc530699261eb60e53reads the raw request body, validates the signature first, and only then parses JSON.Verified vulnerable on tag
v2026.3.24and fixed onmainby commit5e8cb22176e9235e224be0bc530699261eb60e53.Fix Commit(s)
5e8cb22176e9235e224be0bc530699261eb60e53References