Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-rm2p-j3r7-4x4j
No affected components available
Summary
OpenClaw Slack monitor handled reaction_* and pin_* non-message events before applying sender-policy checks consistently.
In affected versions, these events could be added to system-event context even when sender policy would not normally allow them.
Affected Packages / Versions
- Package: npm
openclaw - Latest published affected version confirmed:
2026.2.24(npm latest as of February 26, 2026) - Affected range:
<= 2026.2.24 - Patched version :
2026.2.25
Technical Details
reaction_*andpin_*handlers now route through shared sender authorization (authorizeSlackSystemEventSender).- Enforced checks now include:
- DM
dmPolicy/allowFrom - channel
usersallowlist enforcement for non-DM channels - channel-level allow checks before system-event enqueue
- DM
- Regression coverage added for DM allow/deny and channel-user allowlist deny paths.
Fix Commit(s)
aedf62ac7e669a89c7b299201bf6537dc6b12e0e75dfb71e4e8b7c2feba5a8ca662f92ea840e0147
Impact
Low-severity policy-consistency issue in Slack non-message event ingress. This may introduce unexpected reaction/pin context signals from senders outside configured policy.
Release Process Note
patched_versions is pre-set to planned release 2026.2.25. Advisory published with npm release 2026.2.25.
OpenClaw thanks @tdjackey for reporting.
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a low impact on the integrity of the data.
Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard