In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @openclaw/zalouser to version 2026.3.12 or higher.
@openclaw/zalouser is an OpenClaw Zalo Personal Account plugin via native zca-js integration
Affected versions of this package are vulnerable to Incorrect Authorization in the channels.zalouser.groups. An attacker can gain unauthorized access to restricted channels by reusing a display name that matches an allowlisted group, exploiting the use of mutable group names instead of stable group identifiers for authorization.