VYPR

slack

by OpenClaw

CVEs (1)

  • CVE-2026-100531MedSep 26, 2026
    risk 0.35cvss 6.5epss —

    The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization check fails open. An authenticated…