Executive brief
OpenClaw, a tool used for managing Slack-based agents and gateways, contains a flaw in how it identifies users. An attacker with a Slack account can change their own display name to impersonate a more privileged user, potentially gaining unauthorized access to sensitive agent functions and data. This could lead to an unauthorized user performing actions or accessing information intended only for specific authorized personnel.
Technical details
OpenClaw's 'allowFrom' feature incorrectly uses mutable Slack display names for authentication and policy enforcement rather than immutable Slack user IDs. An attacker with basic Slack account access (PR:L) can modify their display name metadata to match a name listed in an OpenClaw policy entry. This spoofing (CWE-290) allows the attacker to bypass authentication and gain the agent access privileges intended for the legitimate identity. The vulnerability is resolved in version 2026.5.3; users are advised to upgrade or switch to using stable Slack user IDs in their allowlists as a mitigation.
Affected products
- OpenClaw OpenClaw < 2026.5.3
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date