#VU125288 Missing support for integrity check in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to install tampered plugin archives.
The vulnerability exists due to missing support for integrity check in ClawHub package downloads when downloading plugin archives. A local user can provide a tampered archive to install tampered plugin archives.
This issue is scoped to the product's local trust model and does not assume a multi-tenant service boundary.