Code Injection in OpenClaw - #VU127887

 

Code Injection in OpenClaw - #VU127887

Published: April 25, 2026


Vulnerability identifier: #VU127887
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: OpenClaw
Affected software:
OpenClaw

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the bundled plugin setup resolver when resolving provider setup metadata from an attacker-controlled current working directory. A remote attacker can place a crafted setup-api.js file in extensions//setup-api.js and trick the victim into running an OpenClaw command from that directory to execute arbitrary code.

User interaction is required to run OpenClaw from a directory containing the attacker-controlled setup file.


Remediation

Install security update from vendor's website.

Sources