
CVE-2026-41377 OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exp… https://www.cve.org/CVERecord?id=CVE-2026-41377
Post summary
CVE-2026-41377 describes a fail-open flaw in OpenClaw that allows plugin installation to proceed even when security scans fail, potentially exposing vulnerabilities.
