MEDIUM
OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
Published Apr 28, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.33%
Description
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
References (12)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26086 Advisory
- https://github.com/advisories/GHSA-cwq8-6f96-g3q4 Advisory
- https://github.com/openclaw/openclaw/0d7f1e2c84eca65df7dee890d9c30e2a841c030a
- https://github.com/openclaw/openclaw/44b993613601280d46a5b88190e46669fc13d669
- https://github.com/openclaw/openclaw/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68
- https://github.com/openclaw/openclaw/commit/0d7f1e2c84eca65df7dee890d9c30e2a841c030a patch
- https://github.com/openclaw/openclaw/commit/44b993613601280d46a5b88190e46669fc13d669 patch
- https://github.com/openclaw/openclaw/commit/7a953a52271b9188a5fa830739a4366614ff9916 patch
- https://github.com/openclaw/openclaw/commit/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cwq8-6f96-g3q4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41377
- https://www.vulncheck.com/advisories/openclaw-fail-open-security-scan-bypass-in-plugin-installation third-party-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Reserved Apr 20, 2026
Link CVE-2026-41377
CISA Vulnrichment
Updated Apr 29, 2026
ENISA EUVD
EUVD-2026-26086 GHSA-CWQ8-6F96-G3Q4 Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Exploited since n/a
Link EUVD-2026-26086