OpenClaw plugins/extensions run in-process and are treated as trusted code. This advisory tracks trust-boundary clarification around plugin runtime command execution (runtime.system.runCommandWithTimeout).
Plugins already execute with the same OS privileges as the OpenClaw process. Exposing runtime command helpers does not cross an additional sandbox boundary.
openclaw (npm)2026.2.17<= 2026.2.172026.2.19 (next release line)2e421f32dfc589c02706265fd3c3137ffc06c4b1plugins.allow to pin explicit trusted plugin IDs.OpenClaw thanks @markmusson for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T21:39:26Z",
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"nvd_published_at": null
}