PT-2026-34785 · Openclaw · Openclaw

Steven Siegfried

·

Published

2026-04-07

·

Updated

2026-04-25

·

CVE-2026-41354

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.2
Description An insufficient scope issue exists in Zalo webhook replay dedupe keys. This allows legitimate events from different senders or conversations to collide, enabling attackers to exploit weak deduplication scoping to cause silent message suppression and disrupt bot workflows across chat sessions.
Recommendations Update to version 2026.4.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41354
GHSA-6477-WVJJ-47V6
GHSA-RXMX-G7HR-8MX4

Affected Products

Openclaw