Executive brief
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code via a crafted .npmrc file.
Affected products
- openclaw openclaw
References
- https://api.github.com/users/ChangeYourWay
- https://github.com/ChangeYourWay
- https://api.github.com/users/ChangeYourWay/gists%7B/gist_id%7D
- https://api.github.com/users/ChangeYourWay/repos
- https://avatars.githubusercontent.com/u/167730365?v=4
- https://api.github.com/users/ChangeYourWay/events%7B/privacy%7D