CVE-2026-41374
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist validation to cause resource exhaustion.
MEDIUM · CVSS 5.3
EPSS 0.00081
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0