Junglewise Threat Intelligence

CVE-2026-32920: OpenClaw arbitrary code execution via untrusted plugin auto-discovery

CVE-2026-32920 · Severity: high · CVSS 8.4 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a development tool, contains a security flaw where it automatically runs code from plugins found in a project folder without asking for permission. If a user downloads a malicious project and runs OpenClaw within that folder, the tool will automatically execute hidden malicious code. This could allow an attacker to take full control of the user's computer, steal data, or install malware.

Technical details

OpenClaw versions prior to 2026.3.12 are vulnerable to arbitrary code execution due to an insecure plugin discovery mechanism. The application automatically loads and executes scripts located in the '.OpenClaw/extensions/' directory of the current workspace without requiring user consent or verifying the trust level of the workspace. An attacker can exploit this by distributing a malicious repository (e.g., via Git) containing a crafted plugin. When a victim clones the repository and executes OpenClaw from within that directory, the malicious code is executed with the privileges of the user. This vulnerability is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). The issue is resolved in version 2026.3.12, which introduces an explicit trust verification step before loading workspace plugins.

Affected products

  • OpenClaw OpenClaw < 2026.3.12

Timeline

  • 2026-03-13: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: NVD publication date
  • 2026-03-12: patched: Version 2026.3.12 released

References

Related threats