LOW
OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands
Published Apr 23, 2026
2.3
LOWCVSS 4.0
EPSS 0.31%
Description
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group DM channel allowlist restrictions. Authorized Discord users can bypass channel restrictions by invoking slash commands, allowing access to restricted group DM channels.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25332 Advisory
- https://github.com/advisories/GHSA-rvvf-6vh3-9j43 Advisory
- https://github.com/openclaw/openclaw/commit/8fdb19676ab44cf85d47ee13c578195f2e527591 patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- https://github.com/openclaw/openclaw/security/advisories/GHSA-rvvf-6vh3-9j43 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41348
- https://www.vulncheck.com/advisories/openclaw-group-dm-channel-allowlist-bypass-via-discord-slash-commands third-party-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 20, 2026
Link CVE-2026-41348
CISA Vulnrichment
Updated Apr 24, 2026
ENISA EUVD
EUVD-2026-25332 GHSA-RVVF-6VH3-9J43 Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Exploited since n/a
Link EUVD-2026-25332