CVE-2026-43571
OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time plugin loading.
View on NVDAnalysis
OpenClaw appears to be a niche tool or specialized game engine recreation that is not part of the standard web, mobile, or backend developer stack. While the CVSS 8.8 score and the plugin trust bypass are significant for users of this software, it does not meet the threshold for community-wide relevance given its limited deployment.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-829EPSS
Technical description
OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time plugin loading.