No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 16 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input. | |
| Title | OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-16T18:55:36.416Z
Reserved: 2026-06-10T21:21:12.125Z
Link: CVE-2026-53851
Updated: 2026-06-16T18:43:06.532Z
Status : Awaiting Analysis
Published: 2026-06-16T19:17:02.327
Modified: 2026-06-16T20:42:46.200
Link: CVE-2026-53851
No data.
OpenCVE Enrichment
Updated: 2026-06-16T20:15:16Z