Junglewise Threat Intelligence

OpenClaw authorization bypass in Slack reaction event processing

Severity: medium · CVSS 5.3 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an automation agent platform, contains a flaw where it may process Slack emoji reactions even when reaction notifications are turned off. This could allow an unauthorized user to trigger automated workflows or data processing by simply reacting to messages in a connected Slack channel. While the impact depends on how the agent is configured, it could lead to the processing of untrusted data or unintended system actions.

Technical details

OpenClaw before version 2026.5.12 is vulnerable to a missing authorization check (CWE-862) in its Slack event handling logic. Specifically, Slack reaction events are permitted to enter the agent's processing pipeline regardless of the 'reaction notification' configuration setting. An unauthenticated attacker on a connected Slack workspace can trigger unintended agent execution by sending reaction events. This bypass allows lower-trust input to reach the agent's execution surface, potentially leading to unauthorized processing or integrity impacts depending on the agent's capabilities. The issue is resolved in version 2026.5.12.

Affected products

  • openclaw openclaw < 2026.5.12

Timeline

  • 2026-05-28: advisory: Original GHSA-fcvx-5cxc-v5p8 published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53851
  • 2026-06-18: patched: Advisory updated to reflect patch availability in 2026.5.12

References

Related threats