HIGHCVE-2026-42428Published Modified CNA VulnCheck
CVE-2026-42428: OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads
OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.
Metrics
- CVSS v4.0
- 7.5
- Severity
- HIGH
- Fixed in
- 2026.4.8
- Affected Products
- 1
Affected packages
- OpenClaw / OpenClaw< 2026.4.8 (from 0)Fixed in 2026.4.8
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N