clawsmith.com/signal/cve-2026-45004-arbitrary-code-execution-plugin-setup
⚠ IssueWide OpenLive
CVE-2026-45004: Arbitrary Code Execution in OpenClaw Plugin Setup Resolver
OpenClaw before 2026.4.23 allows arbitrary code execution via a malicious setup-api.js file placed in a repository extensions directory. When a user runs OpenClaw commands from that directory, the resolver loads and executes the attacker-controlled JavaScript.
Product Idea from this Signal
A CLI tool that scans a running OpenClaw instance for active CVEs, malicious skills, and supply chain tampering before they get exploited
807 ▲CLIOPEN-SOURCESECURITYDEVTOOLAUDIT
CompetitiveView Opportunity →
Score Breakdown
Issues
7
GitHub
1
Social Proof 2 sources
Frequently Asked Questions
Virality Score
8
across 0 platforms
Details
Signalissue
Ecosystem—
Sources2
Platforms0
Updated27d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →