MEDIUM 5.4 npm
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
GHSA-6336-qqw9-v6x6 · CVE-2026-41341
Published · Modified
Description
Summary
Discord Component Interaction Misclassifies Group DM as Direct Message
Current Maintainer Triage
- Status: narrow
- Normalized severity: low
- Assessment: Real on shipped v2026.3.24 component-interaction routing/auth in extensions/discord/src/monitor/agent-components-helpers.ts, but impact is limited to Group DM policy or session misclassification.
Affected Packages / Versions
- Package:
openclaw(npm) - Latest published npm version:
2026.3.31 - Vulnerable version range:
<=2026.3.28 - Patched versions:
>= 2026.3.31 - First stable tag containing the fix:
v2026.3.31
Fix Commit(s)
8c83128fc38d5a3642b8ccbea58550755fdbbbaf— 2026-03-30T11:17:53-06:00
Release Process Note
- The fix is already present in released version
2026.3.31. - This draft looks ready for final maintainer disposition or publication, not additional code-fix work.
Thanks @nexrin for reporting.
References
- WEB https://github.com/openclaw/openclaw/security/advisories/GHSA-6336-qqw9-v6x6
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-41341
- WEB https://github.com/openclaw/openclaw/commit/8c83128fc38d5a3642b8ccbea58550755fdbbbaf
- PACKAGE https://github.com/openclaw/openclaw
- WEB https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- WEB https://www.vulncheck.com/advisories/openclaw-component-interaction-misclassification-in-discord-extension
Ready to move
Start Securing
Free, no credit card | First findings in minutes