CVE-2026-33576 - OpenClaw < 2026.3.28 - Unauthorized Media Download via Zalo Channel
CVE ID :CVE-2026-33576
Published : March 31, 2026, 2:10 p.m. | 55 minutes ago
Description :OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subsequently rejected.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 31, 2026, 2:10 p.m. | 55 minutes ago
Description :OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subsequently rejected.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...