GHSA-c8w7-9w9h-x69qMedium· 5.3▾ SunlitDuplicate Advisory: Slack reaction events could ignore reaction notification settings
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-fcvx-5cxc-v5p8. This link is maintained to preserve external references.
OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input.
openclaw <= 2026.5.7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53851Medium· 5.3OpenClaw: Slack reaction events could ignore reaction notification settings
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-hcm3-8f6r-6xwgMedium· 6.5OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
GHSA-3wqp-prf6-2m72Low· 3.1OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
CVE-2026-53818Medium· 6.6OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance