Openclaw cli: OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input (CVE-2026-43534)
Description
Openclaw CLI versions before 2026.4.10 contain a vulnerability where agent hook events can enqueue trusted system events from unsanitized external input. This allows untrusted input to be treated as higher-trust context within the agent. The issue is fixed in version 2026.4.10 and later.
CVSS v3.1
Score 9.1critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Openclaw CLI (npm package) prior to version 2026.4.10 has a vulnerability (CVE-2026-43534) where agent hook dispatch can convert externally supplied hook metadata into trusted system events without proper sanitization. This flaw allows untrusted input to be processed as if it originated from a trusted source, potentially leading to privilege escalation or unauthorized actions within the agent. The fix involves sanitizing hook names and marking agent hook system events as untrusted before enqueueing them. The vulnerability was patched in commit e3a845bde5b54f4f1e742d0a51ba9860f9619b29 and released starting with version 2026.4.10.
Potential Impact
This vulnerability allows an attacker to inject untrusted input into the agent as higher-trust system events, which could lead to unauthorized actions or compromise of the agent's integrity. The CVSS score is 9.1 (critical), indicating high impact on confidentiality and integrity without requiring privileges or user interaction.
Mitigation Recommendations
Users should upgrade to Openclaw CLI version 2026.4.10 or later to remediate this vulnerability. The fix is included starting with version 2026.4.10, and the latest release 2026.4.14 contains the patch. No additional mitigation steps are required once the upgrade is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-43534
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac2459512601ec6a3165ca9
Added to database: 10/04/2026, 12:24:53 UTC
Last enriched: 10/04/2026, 12:42:13 UTC
Last updated: 10/04/2026, 16:08:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.