CVE-2026-32920
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-829
Source
NVD
Vendor
OpenClaw
Product
OpenClaw
Discussion (0)
Add Comment
No comments yet. Be the first!