CVE-2026-41377
MEDIUM4.6CVSS v3
—CVSS v2
0.23%
EPSS (exploit probability)
CWE-636CWE
Description
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed despite visible scan warnings.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.