CVE-2026-53851

EUVD-2026-37153
OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
openclawopenclaw
𝑥
< 2026.5.12
openclawopenclaw
2026.5.12:beta1
openclawopenclaw
2026.5.12:beta2
openclawopenclaw
2026.5.12:beta3
openclawopenclaw
2026.5.12:beta4
openclawopenclaw
2026.5.12:beta5
openclawopenclaw
2026.5.12:beta6
openclawopenclaw
2026.5.12:beta7
openclawopenclaw
2026.5.12:beta8
𝑥
= Vulnerable software versions