CVE-2026-41377
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.
Kelemahan
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.
Produk terdampak
- openclaw openclaw
Referensi
- https://github.com/openclaw/openclaw/commit/0d7f1e2c84eca65df7dee890d9c30e2a841c030a
- https://github.com/openclaw/openclaw/commit/44b993613601280d46a5b88190e46669fc13d669
- https://github.com/openclaw/openclaw/commit/7a953a52271b9188a5fa830739a4366614ff9916
- https://github.com/openclaw/openclaw/commit/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cwq8-6f96-g3q4
- https://www.vulncheck.com/advisories/openclaw-fail-open-security-scan-bypass-in-plugin-installation
Temukan bug sebelum penyerang menemukannya.
Masuk dengan GitHub dan jalankan audit pertama Anda dalam waktu kurang dari satu menit. Paket gratis tidak memerlukan kartu kredit.