CVE-2026-41341
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026
Description
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
5.40
Severity 3.x
MEDIUM



