🛡️ CVE-2026-34425 — openclaw

🟡 CVSS 5.4 — Medium ✅ No Known Exploit CWE-184 OSV
5.4
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Summary

Before OpenClaw 2026.4.2, exec script preflight validation could fail open on complex interpreter invocations such as pipes or other non-simple command forms. In those cases, script-content validation could be skipped entirely.

Impact

An attacker-controlled command shape could bypass the intended preflight validation for script execution. This weakened a defense-in-depth guard that was meant to block unsafe script content before execution.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: <= 2026.4.1
  • Patched versions: >= 2026.4.2
  • Latest published npm version: 2026.4.1

Fix Commit(s)

  • 8aceaf5d0f0ec552b75a792f7f0a3bfa5b091513 — close the fail-open bypass in exec script preflight

Release Process Note

The fix is present on main and is staged for OpenClaw 2026.4.2. Publish this advisory after the 2026.4.2 npm release is live.

Thanks @iskindar for reporting, and thanks @wsparks-vc for coordination.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality low, integrity low, availability none.

Affected software

CVE-2026-34425 is recorded against 1 package.

  • openclaw

Timeline and source

Published on 6 April 2026 and last revised on 24 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
www.vulncheck.com (Web)

Details

Severity MEDIUM
CVSS Score 5.4
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE CWE-184
Public Exploit ✅ No
Source OSV
Published 2026-04-06
Updated 2026-08-12
Modified 2026-07-24

Affected Packages

Software From version Fixed in
openclaw

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in openclaw

CVE-2026-34425 is rated CVSS 5.4 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.