
CVE-2026-41354 OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or… https://www.cve.org/CVERecord?id=CVE-2026-41354
Post summary
The post announces CVE‑2026‑41354 in OpenClaw before 2026.4.2, noting an insufficient-scope flaw in Zalo webhook replay dedupe keys that could allow legitimate events from different conversations. No PoC, exploit tool, or patch is provided, nor are there indications of active exploitation.
