High severity8.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-53810
CVE-2026-53810
Description
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-v6r2-jh58-xx6wnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unscanned-marketplace-runtime-extension-metadatanvdThird Party Advisory
News mentions
1- OpenClaw: 14 Vulnerabilities Disclosed in Single Batch, Including Code Execution and Privilege EscalationVypr Intelligence · Jun 11, 2026