CVE-2026-62222: OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62222?
CVE-2026-62222 has a severity level of high with a score of 7.1.
How do I fix CVE-2026-62222?
To fix CVE-2026-62222, upgrade OpenClaw to version 2026.5.22 or later.
What type of vulnerability is CVE-2026-62222?
CVE-2026-62222 is a vulnerability related to untrusted plugin loading via setup-mode.
Who can exploit CVE-2026-62222?
Attackers with lower-trust caller access or control over configured input paths can exploit CVE-2026-62222.
What impact does CVE-2026-62222 have on OpenClaw?
CVE-2026-62222 allows attackers to execute or persist actions beyond their intended authorization level.