CVE-2026-53810

HIGH

OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension Metadata

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
GitHub Security Advisory (GHSA-v6r2-jh58-xx6w)
https://github.com/openclaw/openclaw/security/advisories/GHSA-v6r2-jh58-xx6w

Scores

CVSS v3 8.8
EPSS 0.0042
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-829
Status published
Products (3)
OpenClaw/OpenClaw < 2026.5.18
openclaw/openclaw < 2026.5.18
OpenClaw/OpenClaw 2026.5.18
Published Jun 11, 2026
Tracked Since Jun 12, 2026