PT-2026-23522 · Openclaw · Openclaw

Akhmittra

·

Published

2026-03-03

·

Updated

2026-03-11

·

CVE-2026-28393

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2.0.0-beta3 through 2026.2.13
Description The OpenClaw software contains a path traversal issue within the hook transform module loading process that could lead to arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter is susceptible to accepting absolute paths and traversal sequences. An attacker with configuration write access can leverage this to load and execute malicious modules with gateway process privileges. The issue arises because path resolution previously accepted absolute paths and did not enforce containment for relative paths, allowing a config-controlled transform to resolve outside the intended transforms directory.
Recommendations Update OpenClaw to version 2026.2.14 or later.

Fix

Uncontrolled Search Path Element

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-28393
GHSA-7XHJ-55Q9-PC3M

Affected Products

Openclaw