High severity8.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-53810
CVE-2026-53810
Description
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.5.18 | 2026.5.18 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-v6r2-jh58-xx6wghsaADVISORY
- github.com/openclaw/openclaw/security/advisories/GHSA-v6r2-jh58-xx6wnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-53810ghsaADVISORY
- www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unscanned-marketplace-runtime-extension-metadatanvdThird Party AdvisoryWEB
News mentions
1- OpenClaw: 14 Vulnerabilities Disclosed in Single Batch, Including Code Execution and Privilege EscalationVypr Intelligence · Jun 11, 2026