Executive brief
OpenClaw, a tool used for integrating with the Mattermost messaging platform, contains a security flaw in how it handles incoming messages. An attacker can bypass security policies intended to restrict certain content or actions by sending specially crafted messages that omit specific metadata. This could allow unauthorized processing of restricted content, potentially leading to policy violations within the communication environment.
Technical details
An improper access control vulnerability (CWE-636) exists in OpenClaw's Mattermost event handlers. The software fails to properly validate channel type metadata when processing incoming events. By sending a crafted Mattermost event that lacks channel type information, an attacker can cause the handler to 'fail open,' bypassing intended Direct Message (DM) policy decisions. This allows for the processing of restricted content that should have been blocked by channel-specific policies. The vulnerability is reachable over the network but requires specific conditions (high attack complexity and specific attack requirements) to exploit successfully. The issue is resolved in version 2026.5.6.
Affected products
- OpenClaw OpenClaw < 2026.5.6
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date