Junglewise Threat Intelligence

OpenClaw Discord Slash Commands authorization bypass

Severity: low · CVSS 3.1 · Published 2026-04-24

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Discord bot that enforces restrictions on which group DM channels authorized users can access. A flaw in the slash command handler allows authenticated users to bypass these channel restrictions and access group DM channels they should not have permission to view, even though the attacker must already be an authorized Discord user.

Technical details

OpenClaw versions up to 2026.3.28 contain an authorization bypass vulnerability (CWE-863) in Discord slash command and autocomplete paths that fail to enforce group DM channel allowlist restrictions. An already-authorized Discord user can invoke slash commands to bypass channel-level access controls and gain access to restricted group DM channels. The vulnerability requires prior authorization as a Discord user but allows escalation within the application's permission model. The fix is available in version 2026.3.31 and later.

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: patched: Fix released in version 2026.3.31
  • 2026-04-24: advisory

References

Related threats