
🔴 CVE-2026-33576 - Critical OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to t... https://www.thehackerwire.com/vulnerability/CVE-2026-33576/ https://t.co/rR6OlZMDOn
Post summary
The tweet discloses a critical vulnerability in OpenClaw 2026.3.28 and earlier, where unauthorized Zalo channel senders can trigger network fetches and disk writes, but it provides no PoC, exploitation code, active usage claims, or patch information.


