VYPR

@openclaw/discord

by OpenClaw

CVEs (1)

  • CVE-2026-100526MedSep 26, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host…