CVE-2026-41358
MEDIUMOpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context
Title source: cnaDescription
OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sender access controls and manipulate model context.
Scores
CVSS v3
5.4
EPSS
0.0001
EPSS Percentile
2.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-346
Status
published
Products (2)
OpenClaw/OpenClaw
< 2026.4.2
OpenClaw/OpenClaw
2026.4.2
Published
Apr 23, 2026
Tracked Since
Apr 24, 2026