{"data":{"id":"1fbc34dd-1054-471d-9e13-e2deee8c711d","title":"GHSA-m3mh-3mpg-37hw: OpenClaw has an Arbitrary Malicious Code Execution Vulnerability","summary":"OpenClaw has a vulnerability where malicious plugins or hooks can execute arbitrary code during installation. An attacker can create a `.npmrc` file (npm's configuration file) in a malicious plugin or hook directory that redirects the git executable to a malicious program, which gets executed when OpenClaw runs `npm install` during the installation phase.","solution":"Fixed in OpenClaw 2026.3.24, the current shipping release.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-m3mh-3mpg-37hw","publishedAt":"2026-03-30T18:52:09.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["openclaw@<= 2025.3.23 (fixed: 2026.3.24)"],"affectedVendors":[],"affectedVendorsRaw":["OpenClaw"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-03-30T18:52:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}