Openclaw cli: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution (CVE-2026-45004)
Description
OpenClaw CLI versions before 2026.4.23 contain a vulnerability where the bundled plugin setup resolver could execute arbitrary JavaScript from an attacker-controlled setup-api.js file located in the current working directory. This occurs when a user runs OpenClaw commands from a directory containing malicious setup files, leading to code execution under the user's privileges. The vulnerability requires user interaction and local access but does not depend on network exposure. The issue is fixed in version 2026.4.23 by restricting setup resolution to the canonical package root and excluding process.cwd().
CVSS v3.1
Score 7.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenClaw's plugin setup resolver previously included process.cwd() as a fallback location for resolving provider setup metadata. If a user ran OpenClaw from a directory controlled by an attacker containing extensions/<plugin>/setup-api.js, OpenClaw would load and execute that JavaScript code. This results in arbitrary code execution within the OpenClaw process under the current user account. The vulnerability is local and requires user interaction, as the user must run OpenClaw from the attacker-controlled directory. The issue is fixed in version 2026.4.23 by removing process.cwd() from the trusted setup-api search roots and limiting resolution to the canonical package root.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript code with the privileges of the user running OpenClaw. This can lead to full compromise of the user's environment where OpenClaw is executed. The attack requires the user to run OpenClaw commands from a directory containing the malicious setup-api.js file, so it is limited to local or social engineering scenarios. There is no network vector for exploitation.
Mitigation Recommendations
A fix is available in OpenClaw version 2026.4.23. Users should upgrade to this version or later to prevent arbitrary code execution via malicious setup-api.js files in the current working directory. The fix removes process.cwd() from the setup resolution fallback paths, ensuring only the canonical package root is trusted. No additional mitigation steps are required once the update is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-45004
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac2458f12601ec6a316414a
Added to database: 10/04/2026, 12:24:47 UTC
Last enriched: 10/04/2026, 12:38:37 UTC
Last updated: 10/04/2026, 16:08:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.