PT-2026-23522 · Openclaw · Openclaw
Akhmittra
·
Published
2026-03-03
·
Updated
2026-03-11
·
CVE-2026-28393
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2.0.0-beta3 through 2026.2.13
Description
The OpenClaw software contains a path traversal issue within the hook transform module loading process that could lead to arbitrary JavaScript execution. The
hooks.mappings[].transform.module parameter is susceptible to accepting absolute paths and traversal sequences. An attacker with configuration write access can leverage this to load and execute malicious modules with gateway process privileges. The issue arises because path resolution previously accepted absolute paths and did not enforce containment for relative paths, allowing a config-controlled transform to resolve outside the intended transforms directory.Recommendations
Update OpenClaw to version 2026.2.14 or later.
Fix
Uncontrolled Search Path Element
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw