CVE-2026-41358

MEDIUM

OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context

Title source: cna

Description

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sender access controls and manipulate model context.

Scores

CVSS v3 5.4
EPSS 0.0001
EPSS Percentile 2.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-346
Status published
Products (2)
OpenClaw/OpenClaw < 2026.4.2
OpenClaw/OpenClaw 2026.4.2
Published Apr 23, 2026
Tracked Since Apr 24, 2026