PT-2026-34779 · Openclaw · Openclaw

Keensecuritylab

+2

·

Published

2026-04-03

·

Updated

2026-04-25

·

CVE-2026-41348

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description An authorization bypass exists in Discord slash command and autocomplete paths that fail to enforce group DM channel allowlist restrictions. This allows authorized Discord users to bypass channel restrictions by invoking slash commands, granting access to restricted group DM channels.
Recommendations Update to version 2026.3.31.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-41348
GHSA-QGP3-3RJ7-QQQ4
GHSA-RVVF-6VH3-9J43

Affected Products

Openclaw