GHSA-v773-r54f-q32w: OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands
When Slack DMs are configured with dmPolicy=open, the Slack slash-command handler incorrectly treated any DM sender as command-authorized. This allowed any Slack user who could DM the bot to execute privileged slash commands via DM, bypassing intended allowlist/access-group restrictions.
References
Code Behaviors & Features
Detect and mitigate GHSA-v773-r54f-q32w with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →