Home

Description

OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.

PUBLISHED Reserved 2026-04-27 | Published 2026-04-28 | Updated 2026-04-29 | Assigner VulnCheck




HIGH: 7.5CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.1CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-353 Missing Support for Integrity Check

Product status

Default status
unaffected

Any version before 2026.4.8
affected

2026.4.8 (semver)
unaffected

Credits

KEXNA (@kexinoh) reporter

References

github.com/...enclaw/security/advisories/GHSA-3vvq-q2qc-7rmp (GitHub Security Advisory (GHSA-3vvq-q2qc-7rmp)) vendor-advisory

github.com/...ommit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 (Patch Commit) patch

www.vulncheck.com/...grity-verification-in-package-downloads (VulnCheck Advisory: OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads) third-party-advisory

cve.org (CVE-2026-42428)

nvd.nist.gov (CVE-2026-42428)

Download JSON