PT-2026-29228 · Openclaw · Openclaw

Lintsinghua

·

Publicado

2026-03-13

·

Atualizado

2026-03-31

·

CVE-2026-32920

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.12
Description OpenClaw automatically discovers and loads plugins from the .OpenClaw/extensions/ directory without verifying their trustworthiness, which can lead to arbitrary code execution. An attacker can exploit this by including malicious workspace plugins in cloned repositories. When a user runs OpenClaw from such a directory, the malicious code is executed. The application automatically ingests extensions from the .OpenClaw/extensions/ path, increasing the risk of arbitrary code execution as malicious code could be executed without verification.
Recommendations Update OpenClaw to version 2026.3.12 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32920
GHSA-99QW-6MR3-36QR
GHSA-J5QH-5234-4RQP

Produtos afetados

Openclaw