Openclaw cli: OpenClaw: Slack allowFrom could bind to mutable display names (CVE-2026-53823)
Description
A vulnerability in OpenClaw CLI's Slack integration allows the 'allowFrom' policy to bind to mutable Slack display names. This means a Slack account that can change its display name metadata might match a policy entry incorrectly, potentially receiving agent access intended for another Slack identity. The issue affects versions from 2026.1.29 up to but not including 2026.5.4. The vulnerability does not alter OpenClaw's trusted-operator model. A fix is available starting with version 2026.5.3. Until patched, using stable Slack user IDs in allowlists and narrowing channel and tool allowlists are recommended mitigations.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenClaw CLI Slack 'allowFrom' feature binds policy entries to Slack display names, which are mutable. This allows a Slack user who can change their display name metadata to impersonate or gain access intended for another Slack identity if the feature is enabled and reachable. The vulnerability is scoped to this feature and does not affect the overall trusted-operator model of OpenClaw. The first stable patched version is 2026.5.3. The affected versions are >=2026.1.29 and <2026.5.4.
Potential Impact
If the vulnerable feature is enabled and accessible, an attacker controlling a Slack account capable of changing its display name metadata could receive agent access intended for a different Slack identity. The practical impact depends on the operator's configuration and whether untrusted input can reach the affected feature. This could lead to unauthorized access within the OpenClaw environment via Slack identity confusion.
Mitigation Recommendations
A patch is available starting with OpenClaw CLI version 2026.5.3. Until systems are updated, operators should use stable Slack user IDs in allowlists instead of display names. Additionally, operators should keep channel and tool allowlists narrow, avoid sharing a Gateway between mutually untrusted users, and disable the affected Slack feature when it is not needed.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-53823
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac2458f12601ec6a3164143
Added to database: 10/04/2026, 12:24:47 UTC
Last enriched: 10/04/2026, 12:37:49 UTC
Last updated: 10/04/2026, 16:08:39 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.