CVE-2026-41362

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
28/04/2026
Last modified:
28/04/2026

Description

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitimate events on different accounts by matching event_name and message_id parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* 2026.2.19 (including) 2026.3.31 (excluding)