clawsmith.com/signal/cve-2026-35641-npmrc-arbitrary-code-exec
⚠ IssueWide OpenLive
CVE-2026-35641: OpenClaw .npmrc credential exfiltration and arbitrary code execution (CVSS 8.4)
CVSS 8.4 vulnerability targeting .npmrc files during local plugin installation. Scoped credentials and custom registry entries from plugin-directory .npmrc files were not sanitized, enabling credential theft and arbitrary code execution. Remotely exploitable on unauthenticated instances.
Product Idea from this Signal
A pre-publish scanner that strips source maps, secrets, and internal code from npm packages before they ship to the registry
26143.4k ▲SECURITYCLIDEVTOOLNPMOPEN-SOURCE
Competitive40 leadsView Opportunity →
Product Idea from this Signal
A security service that auto-patches OpenClaw CVEs within hours of disclosure before attackers exploit them
460.5k ▲SECURITYCLIDEVTOOLOPEN-SOURCESYSADMIN
CompetitiveView Opportunity →
Score Breakdown
Issues
84
Social Proof 1 sources
Frequently Asked Questions
Virality Score
84
across 0 platforms
Details
Signalissue
Ecosystem—
Sources1
Platforms0
Updated44d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →