Feishu Raw card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing
openclaw<= 2026.3.242026.3.252026.3.24Feishu raw card sends could previously mint legacy callback payloads that bypassed DM pairing and let unpaired recipients reach callback handling. Commit 81c45976db532324b5a0918a70decc19520dc354 rejects legacy raw-card command payloads so callbacks stay on the normal paired path.
Verified vulnerable on tag v2026.3.24 and fixed on main by commit 81c45976db532324b5a0918a70decc19520dc354.
81c45976db532324b5a0918a70decc19520dc354{
"github_reviewed": true,
"cwe_ids": [
"CWE-288",
"CWE-863"
],
"nvd_published_at": null,
"github_reviewed_at": "2026-03-29T15:49:17Z",
"severity": "MODERATE"
}