Description

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level.

Severity (CVSS)

Base score7.1
SeverityHigh
VersionCVSS 4.0
VectorCVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-829 — Inclusion of Functionality from Untrusted Control Sphere

Affected products

VendorProductVersions
OpenClawOpenClaw0 to <2026.5.22; 2026.5.22

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 17 Jul 2026 07:01 UTC.