PT-2026-29228 · Openclaw · Openclaw

·

CVE-2026-32920

·

Published

2026-03-13

·

Updated

2026-07-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.12
Description OpenClaw automatically discovers and loads plugins from the .OpenClaw/extensions/ directory without explicit trust verification. This allows for arbitrary code execution, as attackers can include crafted workspace plugins in cloned repositories. When a user runs OpenClaw from such a directory, the malicious code is executed under the user's account. This issue occurs because the application fails to verify the integrity of plugins loaded from the specified path.
Recommendations Update to version 2026.3.12 or later. Avoid running OpenClaw inside untrusted repositories on versions prior to 2026.3.12.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32920
GHSA-99QW-6MR3-36QR
GHSA-J5QH-5234-4RQP

Affected Products

Openclaw