Executive brief
OpenClaw is an AI automation platform that integrates with messaging services like Discord, Slack, and Telegram. The vulnerability allows users who are not on an allowlist to trigger system events by reacting to bot-authored messages in restricted direct-message environments. While reactions alone do not execute commands, they can enqueue downstream automation tasks, potentially allowing unauthorized users to interact with the system in environments where they should be blocked.
Technical details
The vulnerability is a missing authorization check (CWE-863) in the Discord reaction-notification ingress path. The DM message path correctly enforces dmPolicy/allowFrom checks before processing messages, but the reaction-notification path previously allowed event enqueue without applying the same authorization gate. This creates an inconsistency where unauthorized (non-allowlisted) Discord users can react to bot-authored DMs and trigger system events in restrictively-configured DM setups. The attack requires network access and the ability to react to a message sent by the bot, but no authentication or user interaction is needed beyond that. The fix (version 2026.2.25 and later) aligns reaction ingress with normal message preflight checks for Discord DM, group-DM, and guild policy boundaries, and applies equivalent hardening to Slack and other platforms. The fix was committed on 2026-02-26.
Affected products
- OpenClaw openclaw <=2026.2.24
Timeline
- 2026-03-03: disclosed: GHSA-354r-7mfh-7rh2 published
- 2026-02-25: patched: Version 2026.2.25 released with fix
- 2026-02-26: other: Fix commit aedf62ac7e669a89c7b299201bf6537dc6b12e0e
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-354r-7mfh-7rh2
- https://github.com/openclaw/openclaw/commit/aedf62ac7e669a89c7b299201bf6537dc6b12e0e
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-missing-authorization-check-in-discord-dm-reaction-ingress