clawsmith.com/signal/cve-2026-44109-feishu-webhook-auth-bypass-rce
⚠ IssueWide OpenSecurityLive
CVE-2026-44109: Critical Feishu Webhook Auth Bypass Enables Unauthenticated RCE on OpenClaw (CVSS 9.8)
Two fail-open logic inversions in the Feishu/Lark plugin allow unauthenticated attackers to inject arbitrary events into OpenClaw's command dispatch engine. When execution tools are enabled, this translates to unauthenticated remote code execution. Patched in v2026.4.15.
Product Idea from this Signal
A CLI tool that scans a running OpenClaw instance for active CVEs, malicious skills, and supply chain tampering before they get exploited
807 ▲CLIOPEN-SOURCESECURITYDEVTOOLAUDIT
CompetitiveView Opportunity →
Score Breakdown
GitHub
131
Social Proof 4 sources
Gap Assessment
Wide OpenNo dedicated solution exists
No third-party tool to detect or prevent Feishu webhook auth bypass in OpenClaw deployments
Frequently Asked Questions
Virality Score
131
across 0 platforms
Details
Signalissue
EcosystemSecurity
Sources4
Platforms0
Updated31d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →