Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wpg9-4g4v-f9rc | OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channels |
Fri, 20 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-only tools including gateway and cron functionality in mixed-trust channels. | |
| Title | OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-20T17:56:13.671Z
Reserved: 2026-03-10T19:48:43.187Z
Link: CVE-2026-32035
Updated: 2026-03-20T17:56:07.452Z
Status : Analyzed
Published: 2026-03-19T22:16:39.373
Modified: 2026-04-20T13:43:53.413
Link: CVE-2026-32035
No data.
OpenCVE Enrichment
Updated: 2026-03-20T10:44:18Z
Github GHSA