CVE-2026-41358
## Summary Before OpenClaw 2026.4.2, Slack thread starter and thread-history context fetched through the API was not filtered by the effective sender allowlist. Messages from non-allowlisted senders could still enter the agent context when an allowlisted user replied in the same thread. ## Impact A Slack deployment that relied on sender allowlists could still feed non-allowlisted thread content into the model context through thread history. This was a sender-access-control bypass on Slack thread context, not a direct channel-auth bypass. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.4.1` - Patched versions: `>= 2026.4.2` - Latest published npm version: `2026.4.1` ## Fix Commit(s) - `ac5bc4fb37becc64a2ec314864cca1565e921f2d` — filter Slack thread context by the effective allowlist ## Release Process Note The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live. OpenClaw thanks @AntAISecurityLab for reporting.
Properties
- severity
- low
- summary
- OpenClaw: Slack thread context could include messages from non-allowlisted senders
- epss_score
- 0.0014
- cvss_score
- 5.4
- ghsa_published
- 2026-05-04T16:52:21Z
- source_url
- https://github.com/advisories/GHSA-qm77-8qjp-4vcm
- ghsa_updated
- 2026-05-04T16:52:22Z
- ghsa_id
- GHSA-qm77-8qjp-4vcm
- cve_id
- CVE-2026-41358
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.0378
Related Entities (5)
AFFECTS (1)
VULNERABLE_TO (1)
ENRICHED_BY (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph