
CVE-2026-45004 OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during pr… https://www.cve.org/CVERecord?id=CVE-2026-45004
Post summary
The tweet discloses CVE‑2026‑45004, highlighting an arbitrary code execution flaw in OpenClaw’s bundled plugin resolver that loads setup‑api.js from the working directory.
