Authorization Flaw in OpenClaw Slack NPM Package Impacts Data Security
CVE-2026-100531

7.1HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100531?

The authorization flaw in the OpenClaw Slack npm package before version 2026.8.1 allows authenticated users to bypass conversation boundaries when downloading files. If a file lacks the necessary share metadata indicating its association with a specific conversation, the conversation-authorization check fails open. This vulnerability permits a user, who is typically restricted to a single conversation, to access and download file contents from other conversations by simply knowing or acquiring the file identifier. While it does not enable arbitrary file listing or circumvent Slack's authentication mechanisms, it poses a significant risk to the confidentiality of sensitive information shared across conversations.

Affected Version(s)

slack 0 < 2026.8.1

slack 2026.8.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.