Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-32924 โ€” AI Deep Analysis Summary

CVSS 9.8 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: OpenClaw misclassifies Feishu reaction events when `chat_type` is missing. <br>๐Ÿ”ฅ **Consequences**: It treats group chats as private (DM) chats.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **CWE**: CWE-863 (Incorrect Authorization). <br>๐Ÿ” **Flaw**: Logic error in event classification. <br>โš ๏ธ **Root**: Omitted `chat_type` field triggers false 'peer-to-peer' assumption.

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Vendor**: OpenClaw. <br>๐Ÿ“‰ **Affected**: Versions **< 2026.3.12**. <br>๐Ÿค– **Component**: Feishu integration module (Reaction Events).

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Hackers Can**: Inject unauthorized reactions in protected groups. <br>๐Ÿ”“ **Privileges**: Bypass admin/group restrictions. <br>๐Ÿ“Š **Data**: Potential info leakage via unauthorized interactions.

Q5Is exploitation threshold high? (Auth/Config)

โšก **Threshold**: **LOW**. <br>๐Ÿ”‘ **Auth**: None required (PR:N). <br>๐ŸŒ **Network**: Remote (AV:N). <br>๐Ÿ‘ค **UI**: No user interaction needed (UI:N).

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ“œ **Public Exp**: **No** public PoC listed. <br>๐Ÿ”— **Refs**: VulnCheck & GitHub Advisory available. <br>โš ๏ธ **Risk**: High CVSS (9.8) suggests easy theoretical exploitation.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Check**: Scan for OpenClaw < 2026.3.12. <br>๐Ÿ‘€ **Monitor**: Feishu reaction events in groups. <br>โš™๏ธ **Config**: Verify `chat_type` is always present in payloads.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: Yes. <br>๐Ÿ”ง **Patch**: Upgrade to **2026.3.12** or later. <br>๐Ÿ“… **Date**: Published 2026-03-29.

Q9What if no patch? (Workaround)

๐Ÿ›‘ **Workaround**: Enforce strict input validation. <br>๐Ÿšซ **Block**: Reject events missing `chat_type`. <br>๐Ÿ”’ **Policy**: Manually enforce `requireMention` if possible.

Q10Is it urgent? (Priority Suggestion)

๐Ÿšจ **Urgency**: **CRITICAL**. <br>๐Ÿ”ฅ **Priority**: Patch Immediately. <br>๐Ÿ“ˆ **CVSS**: 9.8 (Critical). <br>โณ **Time**: Zero-day risk due to low exploit complexity.