Junglewise Threat Intelligence

CVE-2026-53851: OpenClaw Slack reaction event notification bypass

CVE-2026-53851 · Severity: medium · CVSS 5.3 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an AI assistant platform, contains a flaw where Slack reaction events (such as adding an emoji to a message) are processed even if notifications for those events are disabled. This could allow unauthorized or unintended inputs to trigger automated agent actions, potentially leading to unexpected operations or resource consumption. Organizations using the Slack integration should update to the latest version to ensure their configuration settings are properly enforced.

Technical details

An improper authorization vulnerability (CWE-285) exists in OpenClaw where Slack reaction events bypass configured notification settings. When a Slack reaction event is delivered to the configured application, it may enter the agent pipeline regardless of whether reaction notifications are disabled in the settings. This allows network-based attackers or users to trigger unintended agent processing by simply reacting to messages in Slack. The impact depends on the specific agent configuration and whether the pipeline processes lower-trust inputs. The issue is fixed in version 2026.5.12.

Affected products

  • openclaw openclaw <= 2026.5.7

Timeline

  • 2026-05-28: disclosed: Advisory published to GitHub repository
  • 2026-06-18: advisory: Published to GitHub Advisory Database
  • 2026.5.12: patched: First stable patched version released

References

Related threats