GHSA-782p-5fr5-7fj8

Suggest an improvement
Source
https://github.com/advisories/GHSA-782p-5fr5-7fj8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-782p-5fr5-7fj8/GHSA-782p-5fr5-7fj8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-782p-5fr5-7fj8
Aliases
Published
2026-02-17T18:40:11Z
Modified
2026-02-19T21:32:55Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
Details

Summary

When the Slack integration is enabled, Slack channel metadata (topic/description) could be incorporated into the model's system prompt.

Impact

Prompt injection is a documented risk for LLM-driven systems. This issue increased the injection surface by allowing untrusted Slack channel metadata to be treated as higher-trust system input.

This is relevant only for deployments that enable Slack. In deployments where tool execution is enabled, a successful injection could lead to unintended tool invocations and/or unintended data exposure.

Affected Packages / Versions

  • npm: openclaw < 2026.2.3

Patched Versions

  • npm: openclaw >= 2026.2.3

Mitigation

  • If you do not use Slack: no action required.
  • If you use Slack: upgrade to a patched version.

Fix Commit(s)

  • 35eb40a7000b59085e9c638a80fd03917c7a095e

Thanks @KonstantinMirin for reporting.

Database specific
{
    "cwe_ids": [
        "CWE-74",
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-17T18:40:11Z",
    "nvd_published_at": "2026-02-19T07:17:44Z",
    "severity": "LOW"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-782p-5fr5-7fj8/GHSA-782p-5fr5-7fj8.json"