Untrusted Plugin Loading Vulnerability in OpenClaw by OpenClaw
CVE-2026-62222
7.1HIGH
What is CVE-2026-62222?
OpenClaw versions prior to 2026.5.22 exhibit a security vulnerability that allows untrusted workspace plugins to be loaded through setup-mode discovery. This flaw can be exploited by attackers who possess lower-trust caller access or manage configured input paths. Consequently, these attackers can perform actions that exceed their intended authorization levels, leading to potential misuse of the system.
Affected Version(s)
OpenClaw 0 < 2026.5.22
OpenClaw 2026.5.22
