CVE-2026-41377

MEDIUM EPSS 13.9%
Published Apr 28, 20262mo ago · Modified Jun 17, 20261w ago
5.1 CVSS 4.0
Medium
Find Similar
Published Apr 28, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.

CVSS Details

Base Score
5.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction P
Scope X

Threat Intelligence

EPSS Exploit Probability
13.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-636

Affected Products 1

VendorProductVersionRange
openclawopenclaw* <2026.3.31

References 6

  • github.com https://github.com/openclaw/openclaw/commit/0d7f1e2c84eca65df7dee890d9c30e2a841c030a
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/44b993613601280d46a5b88190e46669fc13d669
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/7a953a52271b9188a5fa830739a4366614ff9916
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68
    Patch
  • github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-cwq8-6f96-g3q4
    Vendor Advisory
  • vulncheck.com https://www.vulncheck.com/advisories/openclaw-fail-open-security-scan-bypass-in-plugin-installation
    Third Party Advisory

Remediation

  • github.com https://github.com/openclaw/openclaw/commit/0d7f1e2c84eca65df7dee890d9c30e2a841c030a
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/44b993613601280d46a5b88190e46669fc13d669
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/7a953a52271b9188a5fa830739a4366614ff9916
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68
    Patch