Impact
The vulnerability resides in OpenClaw’s setup-mode discovery mechanism, allowing an attacker with lower-trust caller access or control over configured input paths to load and execute workspace plugins that the system does not trust. This capability permits the attacker to run arbitrary code or perform persistent actions beyond their intended authorization level, effectively escalating privileges. The weakness is classified as CWE-829 – Improper Restriction of a Pathname or Functional Parameter, exposing the program to unvalidated configuration inputs.
Affected Systems
OpenClaw openclaw software is affected. Users running any version earlier than 2026.5.22 of OpenClaw are impacted; newer releases are not vulnerable. Specific affected versions are denoted as all releases before 2026.5.22.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity risk, though the EPSS score indicates a very low probability of exploitation in the near term (<1%). The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves local manipulation of the setup-mode configuration – an attacker who can control or influence the input paths used by OpenClaw can introduce malicious plugins. Successful exploitation requires only lower-trust access or the ability to modify configuration inputs; no network exposure or special privileges are explicitly required by the CVE text.
OpenCVE Enrichment