Executive brief
OpenClaw is a platform used to manage and automate workflows, often integrating with tools like Slack for approvals. A security flaw in the Slack plugin allows users who only have permission to approve basic execution commands to also approve more sensitive plugin actions. This could allow an unauthorized user to bypass internal controls and trigger actions that should have required higher-level oversight.
Technical details
An authorization bypass vulnerability (CWE-863) exists in OpenClaw's Slack plugin integration. The root cause is an incorrect authorization check where the 'exec' approver gate was erroneously used to validate plugin-specific approval actions. An attacker with low-privileged 'exec' approval permissions can exploit this to approve plugin actions that should be restricted by a different approval split or policy. This allows for privilege escalation within the approval workflow. The issue is resolved in version 2026.5.12; users are advised to update or manually review Slack approval actions and narrow tool allowlists as a mitigation.
Affected products
- OpenClaw openclaw < 2026.5.12
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: NVD publication date
- 2026-05-12: patched: First stable patched version released