
🔴 CVE-2026-33578 - Critical OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open po... https://www.thehackerwire.com/vulnerability/CVE-2026-33578/ https://t.co/ULrMebAewW
Post summary
The post announces a critical CVE-2026-33578 in OpenClaw versions prior to 2026.3.28, describing a sender policy bypass in Google Chat and Zalouser extensions; no exploit, patch, or PoC is disclosed.


