PT-2026-20318 · Openclaw · Openclaw

Konstantinmirin

·

Published

2026-02-17

·

Updated

2026-03-06

·

CVE-2026-24764

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.3
Description OpenClaw is a personal AI assistant. When the Slack integration is enabled, Slack channel metadata (topic/description) can be incorporated into the model's system prompt. This increases the injection surface, allowing untrusted Slack channel metadata to be treated as higher-trust system input. Prompt injection is a known risk for LLM-driven systems. In deployments where tool execution is enabled, a successful injection could lead to unintended tool invocations and/or unintended data exposure.
Recommendations If you do not use Slack, no action is required. If you use Slack, upgrade to version 2026.2.3 or later.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-24764
GHSA-782P-5FR5-7FJ8

Affected Products

Openclaw