UNKNOWNCVE-2026-32920

OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins

Platform

other

Component

openclaw

Fixed in

2026.3.12

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.

How to fix

Actualice OpenClaw a la versión 2026.3.12 o posterior. Esta versión corrige la vulnerabilidad que permite la ejecución de código arbitrario al cargar plugins sin verificación de confianza desde el directorio .OpenClaw/extensions/.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free