Vulnerability Description
OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.4.8 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e8143Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-3vvq-q2qc-7rmpVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-missing-integrity-verification-in-Third Party Advisory
FAQ
What is CVE-2026-42428?
CVE-2026-42428 is a vulnerability with a CVSS score of 7.1 (HIGH). OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the ...
How severe is CVE-2026-42428?
CVE-2026-42428 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42428?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.