CVE-2026-100575: Openclaw Slack
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.
Affected products
- Openclaw Slack: before 2026.8.1 (fixed in 2026.8.1)
Published 2026-09-26. Last modified 2026-10-08.