CVE-2026-42428

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/04/2026
Last modified:
28/04/2026

Description

OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.