CVE-2026-42428 - CERT CVE
ID CVE-2026-42428
Sažetak OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.
Reference
CVSS
Base: 7.1
Impact: 5.9
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 30-04-2026 - 14:05
Objavljeno 28-04-2026 - 19:37