OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
Metrics
Affected Vendors & Products
References
History
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context. | |
| Title | OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-05T11:25:06.675Z
Updated: 2026-05-06T14:12:27.432Z
Reserved: 2026-05-01T16:56:19.948Z
Link: CVE-2026-43534
Updated: 2026-05-06T14:12:23.865Z
Status : Analyzed
Published: 2026-05-05T12:16:19.750
Modified: 2026-05-07T01:53:35.683
Link: CVE-2026-43534
No data.
ReportizFlow