CVE 9.3 CRITICAL

OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events_CVE-2026-43534

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.

AI Analysis

Input validation vulnerability allowing external hook metadata to be enqueued as trusted system events

Basic Information

ID CVE-2026-43534
Source VulnCheck
Published May 5, 2026 at 11:25

Affected Product

Vendor OpenClaw
Product OpenClaw
Affected Versions OpenClaw OpenClaw 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor OpenClaw
Product OpenClaw
Version < 2026.4.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.