Junglewise Threat Intelligence

CVE-2026-62222: OpenClaw untrusted plugin loading in setup-mode discovery

CVE-2026-62222 · Severity: high · CVSS 7.8 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a workspace and plugin management tool, contains a security flaw in its setup-mode discovery feature. This vulnerability allows the system to inadvertently load and run untrusted plugins from unauthorized locations. If exploited, an attacker could execute malicious code or gain unauthorized access to sensitive data, potentially leading to a full system compromise or persistent unauthorized control over the workspace environment.

Technical details

A vulnerability exists in OpenClaw's setup-mode discovery mechanism (CWE-829) where the application fails to properly validate the source of workspace plugins. An attacker with control over configured input paths or lower-trust caller access can force the application to load and execute arbitrary code via untrusted plugins. The exploit requires local access and some level of user interaction (UI:R) to trigger the setup-mode discovery. This can lead to a complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). The issue is addressed in version 2026.5.22; users are advised to upgrade or restrict the setup-mode feature to trusted operators.

Affected products

  • OpenClaw OpenClaw < 2026.5.22

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD and VulnCheck publication date

References

Related threats