OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context. | |
| Title | OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-05T11:25:06.675Z
Reserved: 2026-05-01T16:56:19.948Z
Link: CVE-2026-43534
No data.
Status : Received
Published: 2026-05-05T12:16:19.750
Modified: 2026-05-05T12:16:19.750
Link: CVE-2026-43534
No data.
OpenCVE Enrichment
Updated: 2026-05-05T13:30:25Z