CyberRota Analysis
AI-GeneratedOpenClaw Slack versions prior to 2026.8.1 are vulnerable due to inadequate enforcement of sender allowlists in multi-person direct messages, allowing unauthorized participants to trigger Slack agents. This flaw can lead to unauthorized access to tools and data associated with these agents, posing a significant security risk. Organizations using affected versions should prioritize updating to mitigate potential data breaches and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.