PatchSiren cyber security CVE debrief
CVE-2026-53810 OpenClaw CVE debrief
CVE-2026-53810 is a high-severity vulnerability in OpenClaw. The vulnerability exists in OpenClaw before version 2026.5.18 and allows for code execution where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning. The CVSS score for this vulnerability is 7.7, indicating a high severity.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-11
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-11
- Advisory updated
- 2026-06-12
Who should care
Users of OpenClaw before version 2026.5.18 should be aware of this vulnerability and take steps to mitigate it.
Technical summary
The vulnerability is caused by the ability to manipulate extension metadata to load plugin code outside reviewed package entry points. This allows attackers with trusted operator access to execute code outside of the reviewed package entry points.
Defensive priority
High
Recommended defensive actions
- Upgrade to OpenClaw version 2026.5.18 or later.
- Review and restrict trusted operator access to prevent manipulation of extension metadata.
- Implement additional security scanning measures to detect and prevent loading of unscanned package payloads.
Evidence notes
The vulnerability was published on June 11, 2026, and modified on June 12, 2026. The CVE record and NVD detail pages provide additional information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53810 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53810
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53810 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53810
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-v6r2-jh58-xx6w
[email protected] - Mitigation, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unscanned-marketplace-runtime-extension-metadata
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.