CVE-2026-43534 - OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CVE ID :CVE-2026-43534
Published : May 5, 2026, 11:25 a.m. | 51 minutes ago
Description :OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 5, 2026, 11:25 a.m. | 51 minutes ago
Description :OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...