Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35643

30
FAUCET Score

CVE-2026-35643 is an unvalidated WebView JavascriptInterface vulnerability in OpenClaw versions prior to 2026.3.22 that enables attackers to inject arbitrary instructions and execute malicious code within the Android application context by exploiting the canvas bridge through untrusted web pages. This vulnerability poses a significant risk to any Android application using the affected OpenClaw library versions. The vulnerability carries a CVSS score of 8.8 (HIGH severity) with a network-based attack vector requiring only user interaction, making it relatively easy to exploit. The attack requires no special privileges and can result in high impact across confidentiality, integrity, and availability of the affected system, allowing attackers to potentially compromise sensitive user data and application functionality. Exploitation status indicates this is not currently being actively exploited in the wild, with no known exploit code publicly available and minimal community attention to date. The FAUCET Risk Score of 52.0 and EPSS score of 0.000420 suggest lower immediate exploitation probability, though organizations should still prioritize updating to version 2026.3.22 or later to mitigate the underlying vulnerability before threat actors develop and distribute exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.22CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.22CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.6HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
29.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 34th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.3.22

Vendor Advisories (1)

npmGHSA-cxmw-p77q-wchghigh

OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface

Mar 26, 2026

References

github.com / openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
Patch
github.com / openclaw/openclaw/commit/8b02ef133275be96d8aac2283100016c8a7f32e5
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-cxmw-p77q-wchg
Vendor Advisory
vulncheck.com / advisories/openclaw-arbitrary-code-execution-via-unvalidated-webview-javascriptinterface
Third Party Advisory