GHSA-qf48-qfv4-jjm9: OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image
Feishu upload path resolution could read files outside the configured localRoots sandbox before handing them to the upload path.
References
Code Behaviors & Features
Detect and mitigate GHSA-qf48-qfv4-jjm9 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →