CVE-2026-53810

HIGH

OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension Metadata

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-v6r2-jh58-xx6w)
https://github.com/openclaw/openclaw/security/advisories/GHSA-v6r2-jh58-xx6w

Scores

CVSS v3 8.8
EPSS 0.0042
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-829
Status published
Products (4)
npm/openclaw 0 - 2026.5.18npm
OpenClaw/OpenClaw < 2026.5.18
openclaw/openclaw < 2026.5.18
OpenClaw/OpenClaw 2026.5.18
Published Jun 11, 2026
Tracked Since Jun 12, 2026