OpenClaw Plugin Trust Bypass Vulnerability Affecting OpenClaw by OpenClaw Team
CVE-2026-43571

7.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-43571?

OpenClaw prior to version 2026.4.10 is susceptible to a plugin trust bypass vulnerability. This issue permits the resolution of workspace plugin shadows during channel setup, enabling attackers to execute malicious workspace plugins that can circumvent established trust parameters during the loading of plugins. This circumvention can lead to unauthorized access and compromise the integrity of the channel setup process, posing a significant risk to users of affected versions.

Affected Version(s)

OpenClaw 0 < 2026.4.10

OpenClaw 2026.4.10

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
qclawer
.