PT-2026-29228 · Openclaw · Openclaw
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.12
Description
OpenClaw automatically discovers and loads plugins from the
.OpenClaw/extensions/ directory without explicit trust verification. This allows for arbitrary code execution, as attackers can include crafted workspace plugins in cloned repositories. When a user runs OpenClaw from such a directory, the malicious code is executed under the user's account. This issue occurs because the application fails to verify the integrity of plugins loaded from the specified path.Recommendations
Update to version 2026.3.12 or later.
Avoid running OpenClaw inside untrusted repositories on versions prior to 2026.3.12.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw