{"id":"CVE-2026-32974","aliases":["GHSA-g353-mgv3-8pcj"],"url":"https://o3.security/vulnerability/CVE-2026-32974","summary":"OpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification Token","details":"### Summary\n\nFeishu webhook mode allowed deployments that configured only `verificationToken` without `encryptKey`. In that state, forged inbound events could be accepted because the weaker configuration did not provide the required cryptographic verification boundary.\n\n### Impact\n\nAn unauthenticated network attacker who could reach the webhook endpoint could inject forged Feishu events, impersonate senders, and potentially trigger downstream tool execution subject to the local agent policy.\n\n### Affected versions\n\n`openclaw` `<= 2026.3.11`\n\n### Patch\n\nFixed in `openclaw` `2026.3.12`. Feishu webhook mode now fails closed unless `encryptKey` is configured, and the webhook transport rejects missing or invalid signatures before dispatch. Update to `2026.3.12` or later and configure `encryptKey` for webhook deployments.","published":"2026-03-29T12:44:26.283Z","modified":"2026-08-12T03:51:35.537536345Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.3.12"}],"fix":{"url":"https://github.com/openclaw/openclaw/pull/44087","label":"openclaw/openclaw#44087"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32974.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-g353-mgv3-8pcj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32974"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-forged-event-injection-via-feishu-webhook-verification-token"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/pull/44087"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/7844bc89a1612800810617c823eb0c76ef945804"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/releases/tag/v2026.3.12"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.537536345Z"}}