PT-2026-34785 · Openclaw · Openclaw
Steven Siegfried
·
Published
2026-04-07
·
Updated
2026-04-25
·
CVE-2026-41354
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.2
Description
An insufficient scope issue exists in Zalo webhook replay dedupe keys. This allows legitimate events from different senders or conversations to collide, enabling attackers to exploit weak deduplication scoping to cause silent message suppression and disrupt bot workflows across chat sessions.
Recommendations
Update to version 2026.4.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw