CVE-2026-43571

8.8

OpenClaw · OpenClaw

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins.

Executive summary

OpenClaw before version 2026.4.10 is vulnerable to a plugin trust bypass flaw that permits malicious workspace plugins to shadow bundled channel plugins during setup, posing significant total technical impact.

Vulnerability

This flaw, classified under CWE-829 as Inclusion of Functionality from Untrusted Control Sphere, involves channel setup catalog lookups resolving workspace plugin shadows before bundled channel plugins. The attack vector is network-based with low attack complexity, requiring low privileges and no user interaction.

Business impact

A successful exploitation of this vulnerability can result in total system compromise, potentially leading to unauthorized data access, integrity violations, and complete system downtime. Given the high CVSS score of 8.8, organizations face severe operational and security risks if malicious workspace plugins are successfully leveraged to bypass intended trust gates.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.4.10 or later across all affected environments.

Proactive Monitoring: Monitor deployment logs and system access controls for unauthorized plugin installations or unexpected behavior during channel setup procedures.

Compensating Controls: Implement strict workspace permissions and restrict plugin installation capabilities to authorized administrative users only until updates can be deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

System administrators must treat CVE-2026-43571 with high urgency given its potential for total technical impact. Immediate application of the npm package update to version 2026.4.10 is critical to eliminate the trust bypass vector and secure the workspace plugin loading mechanism.

More OpenClaw CVEs

Sources

Originally found and disclosed by zsx (@zsxsoft), with KeenSecurityLab (coordinator), qclawer (tool), per the CVE Program record.