CVE-2026-100575 UNKNOWN

CVE-2026-100575

Published: 2026-09-26

Description

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…