CVE-2026-24764

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-driven systems. This issue increases the injection surface by allowing untrusted Slack channel metadata to be treated as higher-trust system input. This issue has been fixed in version 2026.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:23

Type Values Removed Values Added
Summary
  • (es) OpenClaw (anteriormente Clawdbot) es un asistente de IA personal que los usuarios ejecutan en sus propios dispositivos. En las versiones 2026.2.2 e inferiores, cuando la integración de Slack está habilitada, los metadatos del canal (tema/descripción) pueden incorporarse al prompt del sistema del modelo. La inyección de prompts es un riesgo documentado para los sistemas impulsados por LLM. Este problema aumenta la superficie de inyección al permitir que los metadatos no confiables del canal de Slack sean tratados como entrada del sistema de mayor confianza. Este problema ha sido solucionado en la versión 2026.2.3.

19 Feb 2026, 18:30

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/35eb40a7000b59085e9c638a80fd03917c7a095e - () https://github.com/openclaw/openclaw/commit/35eb40a7000b59085e9c638a80fd03917c7a095e - Patch
References () https://github.com/openclaw/openclaw/releases/tag/v2026.2.3 - () https://github.com/openclaw/openclaw/releases/tag/v2026.2.3 - Product, Release Notes
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-782p-5fr5-7fj8 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-782p-5fr5-7fj8 - Exploit, Patch, Vendor Advisory

19 Feb 2026, 07:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 07:17

Updated : 2026-06-17 10:23


NVD link : CVE-2026-24764

Mitre link : CVE-2026-24764

CVE.ORG link : CVE-2026-24764


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')