CVE-2026-41341: OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41341?
CVE-2026-41341 is classified as a medium severity vulnerability due to its logic error in component interaction routing.
How do I fix CVE-2026-41341?
To fix CVE-2026-41341, update OpenClaw to version 2026.3.31 or later, which resolves the misclassification issue.
What does CVE-2026-41341 affect?
CVE-2026-41341 affects the OpenClaw Discord extension prior to version 2026.3.31 by misclassifying group direct messages.
How can CVE-2026-41341 impact my system?
If exploited, CVE-2026-41341 can lead to improper routing of messages, potentially exposing private communications.
Is CVE-2026-41341 actively being exploited?
As of now, there is no public information indicating that CVE-2026-41341 is actively being exploited.