Executive brief
OpenClaw is a framework for building Slack-integrated AI applications. In shared Slack workspaces, the product allows administrators to restrict message senders using allowlist rules (allowFrom, DM policy, channel allowlists). A vulnerability in interactive callback processing could allow unauthorized workspace members to bypass these sender checks and inject event text into active sessions, potentially disrupting or manipulating application behavior.
Technical details
OpenClaw skips configured sender authorization checks for some interactive callbacks (block_action, view_submission, view_closed) in shared workspace deployments. The vulnerability exists in the authorization logic for these callback types, allowing them to be accepted before full sender restriction policies are enforced. An unauthorized but authenticated workspace member can exploit this to enqueue system events into an active session. The flaw is in the callback handler itself; it does not provide unauthenticated access or cross-gateway isolation bypass. A patch is available in version 2026.2.25.
Affected products
- OpenClaw openclaw <= 2026.2.24
Timeline
- 2026-02-26: disclosed
- 2026-03-04: advisory
- 2026-02-25: patched: Version 2026.2.25 released with fix