CVE-2026-35641 — Arbitrary Code Execution via .npmrc Targeting (CVSS 8.4)

All OpenClaw instances older than v2026.4.5 are vulnerable to arbitrary code execution through crafted .npmrc files. The attack requires no authentication and can be triggered remotely.

CVE-2026-35641 — Arbitrary Code Execution via .npmrc Targeting (CVSS 8.4)

OpenClaw has disclosed a critical vulnerability, tracked as CVE-2026-35641, that affects all versions older than v2026.4.5. The flaw can lead to arbitrary code execution through crafted .npmrc files, and the attack can be triggered remotely without authentication.

The issue affects OpenClaw instances that process or inspect .npmrc content in a way that lets a malicious file influence how commands are interpreted. In practical terms, an attacker does not need valid credentials to reach the bug, which makes it more serious than a local-only flaw or one that depends on a compromised account.

⚡ New to this?

This is a security flaw in OpenClaw, a tool used in automation and infrastructure workflows. A .npmrc file is a npm configuration file, and the bug lets a specially crafted one make the software run attacker-controlled code.

Non-experts should care because arbitrary code execution means an attacker can potentially take control of a system or use it to spread further. CVSS is a scoring system for severity, and 8.4 is considered high because the attack can be done remotely with no login required.

🦞 OpenClaw angle

If you're running anything older than v2026.4.5, update now. This is a critical vulnerability with a CVSS score of 8.4 — remote code execution with no auth required.

The Common Vulnerability Scoring System, or CVSS, rates the issue at 8.4 out of 10. That places it in the high-severity range and reflects the combination of remote reachability, no authentication requirement, and the possibility of running attacker-controlled code on the affected system.

A .npmrc file is a configuration file used by npm, the Node.js package manager. It normally stores package manager settings such as registry locations, authentication tokens, and install behavior. Because .npmrc files can affect how package operations run, a parsing or handling flaw in this area can become dangerous quickly if an attacker can supply a crafted file.

The vulnerability is identified as arbitrary code execution, which means the attacker can cause the system to run commands of their choosing. That is one of the most serious classes of software flaw because it can let an outsider take control of a service, plant malware, steal data, or pivot deeper into a network depending on what the vulnerable process can access.

The disclosure is especially relevant for teams using OpenClaw in automation or infrastructure workflows, where package metadata and repository files often move between build systems, job runners, and developer machines. In those environments, files like .npmrc may be handled automatically as part of a pipeline rather than reviewed manually, which increases exposure when a parser bug exists.

The vulnerability is tied to OpenClaw versions earlier than v2026.4.5, which means the fixed release is the clear dividing line for whether an instance is exposed. Security teams generally treat issues like this as urgent because no authentication is required and the execution path is remote, not dependent on an insider or a user clicking a file locally.

The CVE number, CVE-2026-35641, is the formal identifier used to track the issue across advisories, scanners, ticketing systems, and patch notes. That makes it easier for administrators to confirm whether their asset inventories include the vulnerable software and to coordinate remediation with the rest of their tooling.

For organizations that depend on OpenClaw, the bug lands in a category that defenders usually prioritize first: remote code execution in a production-facing component. The combination of a public CVE, a high CVSS score, and a low-friction attack path is what makes this disclosure stand out in the security feed, and the affected versions stop at v2026.4.5.

Source: Blink ↗

More from Security News