CVE-2026-41341
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling.
Scoring
- Severity
- LOW
- CVSS base score
- 5.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-351
- Published
- 2026-04-23
- Last modified
- 2026-04-25
Affected products
- OpenClaw OpenClaw
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2025-65960 — Contao is vulnerable to remote code execution in template closures
- CVE-2025-54413 — skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-54412 — skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
- CVE-2025-47939 — TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
- CVE-2025-30510 — Growatt Cloud portal Insufficient Type Distinction
- CVE-2025-32035 — DNN does not check the contents of a file when uploading files