Junglewise Threat Intelligence

CVE-2026-53810: OpenClaw code execution via unscanned marketplace extension metadata

CVE-2026-53810 · Severity: high · CVSS 8.8 · Published 2026-06-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a runtime extension platform, contains a vulnerability where marketplace extensions can bypass security scans. If an administrator installs a malicious or compromised package, the system may load hidden, unvetted code instead of the expected components. This could lead to unauthorized code execution, potentially compromising the entire gateway and any data it manages.

Technical details

A vulnerability in OpenClaw's marketplace extension handling allows runtime loading to be redirected toward hidden package content that bypasses security scanning. The flaw resides in how extension metadata is processed, enabling a malicious package to specify entry points outside of the reviewed and scanned areas. While the attack requires a 'trusted operator' to initiate the installation (User Interaction), the payload itself can be delivered over the network via the marketplace. Successful exploitation allows for arbitrary code execution (CWE-94) and OS command injection (CWE-78) within the context of the Gateway. The issue is resolved in version 2026.5.18.

Affected products

  • OpenClaw openclaw < 2026.5.18

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: patched: First stable patched version 2026.5.18 released.
  • 2026-06-11: advisory: NVD publication date.
  • 2026-07-02: advisory: GitHub Advisory published.

References

Related threats