Junglewise Threat Intelligence

CVE-2026-41295: OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

CVE-2026-41295 · Severity: medium · CVSS 4 · Published 2026-04-07

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that manages plugins and channels for executing tasks across operating systems. A vulnerability in versions up to 2026.4.1 allows a malicious workspace plugin to execute code during the channel setup process without being explicitly trusted by the user, potentially allowing an attacker to gain code execution on affected systems.

Technical details

This is a code execution vulnerability (CWE-829: Inclusion of Functionality from Untrusted Control Sphere) in the channel resolution logic. Before OpenClaw 2026.4.2, the built-in channel setup and login flow would resolve workspace channel shadows without first confirming that the workspace plugin was explicitly trusted in the configuration. An attacker could craft a malicious workspace plugin that claims to provide a bundled channel ID; this untrusted plugin could then execute arbitrary code in-process during setup operations, even while disabled. The fix (commit 53c29df) prevents untrusted workspace channel metadata from overriding setup/login resolution and only permits workspace channel entries during setup if the plugin is already explicitly trusted in the configuration. The attack requires the victim to clone or use a workspace containing the malicious plugin, with execution occurring during the automatic channel setup phase.

Affected products

  • OpenClaw OpenClaw <= 2026.4.1

Timeline

  • 2026-04-07: disclosed: GHSA-2qrv-rc5x-2g2h published
  • 2026-04-07: patched: OpenClaw 2026.4.2 released with fix

References

Related threats