GHSA-p6pm-6pmc-m53cHighCVSS 8.8

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.

🔗 References (4)