CVE-2026-41358: OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context

Published Apr 23, 2026
·
Updated

Summary

Before OpenClaw 2026.4.2, Slack thread starter and thread-history context fetched through the API was not filtered by the effective sender allowlist. Messages from non-allowlisted senders could still enter the agent context when an allowlisted user replied in the same thread.

Impact

A Slack deployment that relied on sender allowlists could still feed non-allowlisted thread content into the model context through thread history. This was a sender-access-control bypass on Slack thread context, not a direct channel-auth bypass.

Affected Packages / Versions

- Package: openclaw (npm) - Affected versions: <= 2026.4.1 - Patched versions: >= 2026.4.2 - Latest published npm version: 2026.4.1

Fix Commit(s)

- ac5bc4fb37becc64a2ec314864cca1565e921f2d — filter Slack thread context by the effective allowlist

Release Process Note

The fix is present on main and is staged for OpenClaw 2026.4.2. Publish this advisory after the 2026.4.2 npm release is live.

OpenClaw thanks @AntAISecurityLab for reporting.

Other sources

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sender access controls and manipulate model context.

MITRE

Affected Software

3 affected componentsFixes available
OpenClaw OpenClaw<2026.4.2
OpenClaw Openclaw Node.js<2026.4.2
npm/openclaw<=2026.4.1
2026.4.2

Event History

Apr 23, 2026
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 4, 2026
Advisory Published
via GitHub·04:52 PM
Data Sourced
via GitHub·04:52 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41358?

CVE-2026-41358 has been classified as a high severity vulnerability due to the potential for unauthorized message injection.

2

How do I fix CVE-2026-41358?

To fix CVE-2026-41358, upgrade OpenClaw to version 2026.4.2 or later, which includes the necessary patches.

3

What does CVE-2026-41358 exploit?

CVE-2026-41358 exploits a failure to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to pass through.

4

Who is affected by CVE-2026-41358?

CVE-2026-41358 affects all users of OpenClaw versions prior to 2026.4.2.

5

Can CVE-2026-41358 be exploited remotely?

Yes, CVE-2026-41358 can be exploited remotely by attackers leveraging Slack thread contexts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203