clawsmith.com/signal/openclaw-git-executable-hijack-npmrc-cve-32920
⚠ IssueWide OpenLive
OpenClaw Git Executable Hijack via .npmrc — CVE-2026-32920 Enables Arbitrary Code Execution During Plugin Install
High-severity vulnerability in OpenClaw v2026.3.13-1 through v2026.3.23 allows arbitrary code execution during local plugin/hook installation. A malicious .npmrc in the project root overrides the git executable path. The --ignore-scripts flag does not prevent this. Fixed in v2026.3.24.
Product Idea from this Signal
A security service that auto-patches OpenClaw CVEs within hours of disclosure before attackers exploit them
3.7k ▲SECURITYCLIDEVTOOLOPEN-SOURCESYSADMIN
CompetitiveView Opportunity →
Social Proof 3 sources
Frequently Asked Questions
Virality Score
0
across 0 platforms
Details
Signalissue
Ecosystem—
Sources3
Platforms0
Updated10d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →