Junglewise Threat Intelligence

CVE-2026-35641: OpenClaw arbitrary code execution in local plugin installation

CVE-2026-35641 · Severity: high · CVSS 8.6 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code via a crafted .npmrc file.

Affected products

  • openclaw openclaw

References

Related threats