Junglewise Threat Intelligence

OpenClaw notification bypass in Slack reaction event handling

Severity: low · CVSS 3.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a workflow automation tool that integrates with Slack to process events. In affected versions, Slack reaction events could bypass disabled notification settings and enter the processing pipeline, allowing attackers to trigger unintended automation workflows and process untrusted input when the feature is enabled. This could lead to unauthorized processing depending on the operator's configuration.

Technical details

The vulnerability is an improper authorization/notification bypass (CWE-862) in OpenClaw versions prior to 2026.5.12. When Slack reaction event notifications are configured but disabled, the feature fails to properly enforce the notification setting, allowing reaction events to bypass the intended controls and enter the agent pipeline. This affects deployments where the Slack integration is enabled and reachable. The attack requires that the affected feature and Slack integration be configured in the target deployment. The impact depends on whether lower-trust input or untrusted tools can reach the affected code path. A patch is available in version 2026.5.12 or later.

Affected products

  • OpenClaw OpenClaw < 2026.5.12

Timeline

  • 2026-05-28: disclosed
  • 2026-05-12: patched: Version 2026.5.12 contains the fix
  • 2026-06-16: advisory: GHSA-fcvx-5cxc-v5p8 published; GHSA-c8w7-9w9h-x69q marked as duplicate
  • 2026-06-18: other: Duplicate advisory GHSA-c8w7-9w9h-x69q withdrawn

References

Related threats