CVE-2026-32920 PUBLISHED

OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins

Assigner: VulnCheck
Reserved: 16.03.2026 Published: 31.03.2026 Updated: 31.03.2026

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor OpenClaw
Product OpenClaw
Versions Default: unaffected
  • affected from 0 to 2026.3.12 (excl.)
  • Version 2026.3.12 is unaffected

Credits

  • lintsinghua reporter

References

Problem Types

  • Inclusion of Functionality from Untrusted Control Sphere CWE