OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
OpenClaw · OpenClawReferences
https://github.com/openclaw/openclaw/commit/0d7f1e2c84eca65df7dee890d9c30e2a841c030ahttps://github.com/openclaw/openclaw/commit/44b993613601280d46a5b88190e46669fc13d669https://github.com/openclaw/openclaw/commit/7a953a52271b9188a5fa830739a4366614ff9916https://github.com/openclaw/openclaw/commit/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68https://github.com/openclaw/openclaw/security/advisories/GHSA-cwq8-6f96-g3q4https://www.vulncheck.com/advisories/openclaw-fail-open-security-scan-bypass-in-plugin-installation