@openclaw/slack@2026.5.12-beta.7

OpenClaw Slack channel plugin for channels, DMs, commands, and app events.

  • latest version

    2026.7.1

  • latest non vulnerable version

  • first published

    3 months ago

  • latest version published

    1 months ago

  • Direct Vulnerabilities

    Known vulnerabilities in the @openclaw/slack package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Authorization

    @openclaw/slack is an OpenClaw Slack channel plugin for channels, DMs, commands, and app events.

    Affected versions of this package are vulnerable to Improper Authorization via the reaction notification process. An attacker can trigger unintended agent processing for reaction events by delivering Slack reaction events even when reaction notifications are disabled. This is only exploitable if the Slack reaction event feature is enabled and reachable.

    How to fix Improper Authorization?

    Upgrade @openclaw/slack to version 2026.5.12 or higher.

    <2026.5.12