CVE-2026-41358: Openclaw

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sender access controls and manipulate model context.

Affected products

  • Openclaw Openclaw: before 2026.4.2 (fixed in 2026.4.2)

Published 2026-04-23. Last modified 2026-06-17.