PT-2026-29256 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-33576

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description OpenClaw does not validate sender authorization before downloading and storing inbound media from Zalo channels. This allows unauthorized senders to initiate network fetches and write data to the media store by sending messages that are later rejected. The issue involves a lack of proper validation when handling media received from Zalo channels.
Recommendations Update OpenClaw to version 2026.3.28 or later.

Fix

Missing Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33576
GHSA-V2V2-F783-358J

Affected Products

Openclaw