Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35641

27
FAUCET Score

OVERVIEW CVE-2026-35641 affects OpenClaw versions prior to 2026.3.24 and involves an arbitrary code execution vulnerability in the local plugin and hook installation mechanism. The vulnerability stems from improper handling of .npmrc files during npm install operations, allowing attackers to override the git executable and execute malicious code through crafted git dependencies. SEVERITY This vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring user interaction but no special privileges. The attack has low complexity and delivers high impact across confidentiality, integrity, and availability. A user must interact with the affected system, typically by running npm install in a directory containing an attacker-controlled .npmrc file, to trigger exploitation. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking hot lists. However, the EPSS score of 0.000070 indicates this threat ranks in the lower percentile of all CVEs, suggesting limited immediate concern. Organizations should prioritize patching to OpenClaw 2026.3.24 or later as a precautionary measure.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.24CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.24CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.4HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 2nd percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: openclawFixed in: 2026.3.24
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-m3mh-3mpg-37hwhigh

OpenClaw has an Arbitrary Malicious Code Execution Vulnerability

Mar 30, 2026

References

github.com / openclaw/openclaw/security/advisories/GHSA-m3mh-3mpg-37hw
ExploitMitigationVendor Advisory
vulncheck.com / advisories/openclaw-arbitrary-code-execution-via-npmrc-in-local-plugin-hook-installation
Third Party Advisory