CRITICAL🇵🇱 Wersja polska

CVE-2026-43534

CVSS 9.3v4.0pub. 2026-05-05upd. 2026-05-07

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.

🤖 AI Analysis
How it works

The vulnerability results from the lack of integrity verification (CWE-345) of external hook metadata before placing it in the system event queue. An attacker provides crafted hook names, which the system incorrectly treats as trusted internal events. As a result, untrusted input data is escalated to a higher trust context of the agent, bypassing permission control mechanisms.

Impact

An attacker can cause privilege escalation by performing operations in the context of a trusted system agent, enabling unauthorized reading and modification of data protected by a higher level of trust.

Mitigation & patch

OpenClaw should be updated to version 2026.4.10 or newer. The patch is available in the project repository (commit e3a845bde5b54f4f1e742d0a51ba9860f9619b29) and described in the official security advisory GHSA-7g8c-cfr3-vqqr.

Who is affected

OpenClaw in versions prior to 2026.4.10

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openclaw

    APP
    Openclaw
    < 2026.4.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-43585CRITICAL9.2PL ✓same product

OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef

CVE-2026-43578CRITICAL9.1PL ✓same product

OpenClaw: privilege escalation przez pominięcie zdarzeń async exec w heartbeat

CVE-2026-43575CRITICAL9.2PL ✓same product

OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC

CVE-2026-43581CRITICAL9.0PL ✓same product

OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox

CVE-2026-44109CRITICAL9.2PL ✓same product

OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE