Netskope Threat Labs

BROWSER-OTHER Slack command injection attempt

IPS-SWG

2 SIDs: 59046, 59047

First seen
August 2026
Last seen
August 2026

Detects web content that exploits CVE-2018-1000006, a command injection in the Slack desktop client's handling of slack:// protocol links. A crafted link can append arguments such as a custom browser subprocess path to the client's launch command, running code when the user follows it.