#VU125156 Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - CVE-2026-32920
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to inclusion of functionality from an untrusted control sphere in workspace plugin auto-discovery and loading from .openclaw/extensions/ when opening or running OpenClaw in a cloned repository. A remote attacker can include a crafted workspace plugin in a repository to execute arbitrary code.
User interaction is required to run OpenClaw from the cloned directory.