CVE-2026-53810
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.
- Affected products
- Openclaw
- Openclaw
- < 2026.5.18
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-829
- NVD status
- Analyzed
- Published
- 2026-06-11
CVE-2026-53810 at NVD
No indexed exploits for CVE-2026-53810 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-53810 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.