Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6336-qqw9-v6x6 | OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message |
Sat, 25 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling. | |
| Title | OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-351 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-25T01:34:11.541Z
Reserved: 2026-04-20T14:05:09.183Z
Link: CVE-2026-41341
Updated: 2026-04-25T01:34:07.322Z
Status : Analyzed
Published: 2026-04-23T22:16:40.477
Modified: 2026-04-29T15:56:08.107
Link: CVE-2026-41341
No data.
OpenCVE Enrichment
Updated: 2026-04-28T07:30:26Z
Github GHSA