OpenClaw Arbitrary Code Execution Vulnerability via Unverified Plugin Auto-Discovery
Vulnerability
A vulnerability in OpenClaw versions prior to 2026.3.12 allows for arbitrary code execution through the automatic discovery and loading of plugins from the '.OpenClaw/extensions/' directory. This process occurs without any trust verification, enabling attackers to execute malicious code by including specially crafted workspace plugins in cloned repositories. The malicious code runs when OpenClaw is launched from the directory containing the compromised repository.
Impact
Exploiting this vulnerability could lead to arbitrary code execution under the user's account.
Remediation
Users are advised to update OpenClaw to version 2026.3.12 or later. After updating, it is recommended to avoid running OpenClaw in untrusted repositories.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
