SCA: security update for openclaw (GHSA-782p-5fr5-7fj8)

low Tenable Self-Hosted Container Security Plugin ID 437792

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions
2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be
incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-driven systems.
This issue increases the injection surface by allowing untrusted Slack channel metadata to be treated as
higher-trust system input. This issue has been fixed in version 2026.2.3. (CVE-2026-24764)

See Also

https://github.com/advisories/GHSA-782p-5fr5-7fj8

Plugin Details

Severity: Low

ID: 437792

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 2/18/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.71

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.8

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-24764

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.4

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/17/2026

Vulnerability Publication Date: 2/17/2026

Reference Information

CVE: CVE-2026-24764