CVE-2026-35641
High Severity
Description
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious cod...
Related Vulnerabilities
- CVE-2026-4432: The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist own HIGH
- CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting HIGH
- CVE-2026-5412: In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. CRITICAL
- CVE-2026-3446: When calling base64.b64decode() or related functions the decoding process would stop after encounter N/A
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
Related Coverage
Threat Actors