Openclaw cli: OpenClaw has an Arbitrary Malicious Code Execution Vulnerability (CVE-2026-35641)
Description
OpenClaw CLI versions from 2026.1.29 up to but not including 2026.3.24 contain a vulnerability where a maliciously crafted .npmrc file in a local plugin or hook directory can hijack the Git executable path during npm install. This allows an attacker to execute arbitrary code locally during the installation phase of plugins or hooks. The issue is fixed in OpenClaw 2026.3.24.
CVSS v3.1
Score 8.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in OpenClaw CLI arises during the installation of local plugins or hooks. When OpenClaw installs these local packages, it copies the source directory to a temporary staging directory and runs 'npm install --omit=dev --silent --ignore-scripts'. Since npm reads the project-level .npmrc file in the staging directory, an attacker can include a .npmrc file that overrides the 'git' executable path. If the package.json includes a Git dependency, npm will invoke the malicious git executable specified in .npmrc, leading to arbitrary code execution during installation. This flaw affects versions >=2026.1.29 and <2026.3.24 and is fixed in version 2026.3.24.
Potential Impact
An attacker who can supply a local plugin or hook directory to OpenClaw can execute arbitrary code on the local system during the installation phase. This can lead to full compromise of the local environment with high confidentiality, integrity, and availability impact as indicated by the CVSS score of 8.6.
Mitigation Recommendations
A fix is available in OpenClaw version 2026.3.24. Users should upgrade to this version or later to remediate the vulnerability. Until upgraded, avoid installing untrusted local plugins or hooks. No other vendor advisory mitigation instructions are provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-35641
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac245ad12601ec6a3166704
Added to database: 10/04/2026, 12:25:17 UTC
Last enriched: 10/04/2026, 12:55:18 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.