Description
OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.
Problem types
CWE-353 Missing Support for Integrity Check
Product status
Any version before 2026.4.8
2026.4.8 (semver)
Credits
KEXNA (@kexinoh)
References
github.com/...enclaw/security/advisories/GHSA-3vvq-q2qc-7rmp (GitHub Security Advisory (GHSA-3vvq-q2qc-7rmp))
github.com/...ommit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 (Patch Commit)
www.vulncheck.com/...grity-verification-in-package-downloads (VulnCheck Advisory: OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads)