CVE-2026-44993
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassi
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct message conversations that should have been blocked by restrictive policies.
MEDIUM · CVSS 5.4
EPSS 0.00039
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0