Skip to main content
EPSS 0.2%top 91%

Openclaw cli: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution (CVE-2026-45004)

0
High
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

OpenClaw CLI versions before 2026.4.23 contain a vulnerability where the bundled plugin setup resolver could execute arbitrary JavaScript from an attacker-controlled setup-api.js file located in the current working directory. This occurs when a user runs OpenClaw commands from a directory containing malicious setup files, leading to code execution under the user's privileges. The vulnerability requires user interaction and local access but does not depend on network exposure. The issue is fixed in version 2026.4.23 by restricting setup resolution to the canonical package root and excluding process.cwd().

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
>=2026.1.29 <2026.4.23

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 12:38:37 UTC

Technical Analysis

OpenClaw's plugin setup resolver previously included process.cwd() as a fallback location for resolving provider setup metadata. If a user ran OpenClaw from a directory controlled by an attacker containing extensions/<plugin>/setup-api.js, OpenClaw would load and execute that JavaScript code. This results in arbitrary code execution within the OpenClaw process under the current user account. The vulnerability is local and requires user interaction, as the user must run OpenClaw from the attacker-controlled directory. The issue is fixed in version 2026.4.23 by removing process.cwd() from the trusted setup-api search roots and limiting resolution to the canonical package root.

Potential Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript code with the privileges of the user running OpenClaw. This can lead to full compromise of the user's environment where OpenClaw is executed. The attack requires the user to run OpenClaw commands from a directory containing the malicious setup-api.js file, so it is limited to local or social engineering scenarios. There is no network vector for exploitation.

Mitigation Recommendations

A fix is available in OpenClaw version 2026.4.23. Users should upgrade to this version or later to prevent arbitrary code execution via malicious setup-api.js files in the current working directory. The fix removes process.cwd() from the setup resolution fallback paths, ensuring only the canonical package root is trusted. No additional mitigation steps are required once the update is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-CVE-2026-45004
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6ac2458f12601ec6a316414a

Added to database: 10/04/2026, 12:24:47 UTC

Last enriched: 10/04/2026, 12:38:37 UTC

Last updated: 10/04/2026, 16:08:38 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses