CVE-2026-41341
MEDIUMDescription
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openclaw | openclaw |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-41341? +
How severe is CVE-2026-41341? +
What products are affected by CVE-2026-41341? +
How do I check if I'm vulnerable to CVE-2026-41341? +
Related Vulnerabilities
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain …
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain …
An attacker can upload an arbitrary file instead of a plant image.
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's …
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users …
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could …