LOW
OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
Published Apr 23, 2026
2.3
LOWCVSS 4.0
EPSS 0.18%
Description
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25325 Advisory
- https://github.com/advisories/GHSA-6336-qqw9-v6x6 Advisory
- https://github.com/openclaw/openclaw/commit/8c83128fc38d5a3642b8ccbea58550755fdbbbaf patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- https://github.com/openclaw/openclaw/security/advisories/GHSA-6336-qqw9-v6x6 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41341
- https://www.vulncheck.com/advisories/openclaw-component-interaction-misclassification-in-discord-extension third-party-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 25, 2026
Reserved Apr 20, 2026
Link CVE-2026-41341
CISA Vulnrichment
Updated Apr 25, 2026
ENISA EUVD
EUVD-2026-25325 GHSA-6336-QQW9-V6X6 Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 25, 2026
Exploited since n/a
Link EUVD-2026-25325