HIGH
OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads
Published Apr 28, 2026
7.5
HIGHCVSS 4.0
EPSS 0.21%
Description
OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.
Affected products
-
- Version 0StatusaffectedConstraints<2026.4.8
- Version 2026.4.8StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.4.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.4.8 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-3vvq-q2qc-7rmp Advisory
- https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-3vvq-q2qc-7rmp vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42428
- https://www.vulncheck.com/advisories/openclaw-missing-integrity-verification-in-package-downloads third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-3vvq-q2qc-7rmp | Advisory | |
| https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-3vvq-q2qc-7rmp | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-42428 | ||
| https://www.vulncheck.com/advisories/openclaw-missing-integrity-verification-in-package-downloads | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Reserved Apr 27, 2026
Link CVE-2026-42428
CISA Vulnrichment
GHSA-3VVQ-Q2QC-7RMP Updated Apr 29, 2026