Description
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist validation to cause resource exhaustion.
Problem types
CWE-408: Incorrect Behavior Order: Early Amplification
Product status
Any version before 2026.3.31
2026.3.31 (semver)
Credits
AntAISecurityLab
References
github.com/...enclaw/security/advisories/GHSA-hhff-fj5f-qg48 (GitHub Security Advisory (GHSA-hhff-fj5f-qg48))
github.com/...ommit/ee52f64226a03efadfdf1e3b759e13424a3d4e41 (Patch Commit)
www.vulncheck.com/...o-preflight-before-member-authorization (VulnCheck Advisory: OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization)