Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41377

21
FAUCET Score

OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.

First published: Apr 28, 2026Last modified: Apr 29, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.31CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.31CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 17th percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.3.31

Vendor Advisories (1)

npmGHSA-cwq8-6f96-g3q4low

OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)

Apr 2, 2026

References

github.com / openclaw/openclaw/commit/0d7f1e2c84eca65df7dee890d9c30e2a841c030a
Patch
github.com / openclaw/openclaw/commit/44b993613601280d46a5b88190e46669fc13d669
Patch
github.com / openclaw/openclaw/commit/7a953a52271b9188a5fa830739a4366614ff9916
Patch
github.com / openclaw/openclaw/commit/bf96c67fd1954740aeabfadc7cfe3098bcfc6b68
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-cwq8-6f96-g3q4
Vendor Advisory
vulncheck.com / advisories/openclaw-fail-open-security-scan-bypass-in-plugin-installation
Third Party Advisory