CVE-2026-45004 - OpenClaw < 2026.4.23 - Arbitrary Code Execution via setup-api.js in Current Working Directory
CVE ID :CVE-2026-45004 Published : May 11, 2026, 6:16 p.m. | 49 minutes ago Description :OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attac
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Google says hackers used AI to exploit ‘zero-day’ flaw
- [CYBER] CVE-2026-42871 - WeGIA: Error Handling familiar_docfamiliar
- [CYBER] Google says hacker used Mythos-like AI for zero-day exploit
- [CYBER] CVE-2026-42866 - Tookie: Arbitrary file write via path traversal in -u username / -U userfile output filename
- [CYBER] CVE-2026-42864 - FireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theft
- [CYBER] CVE-2026-8305 - OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication