PT-2026-23533 · Openclaw · Openclaw

222N5

·

Published

2026-02-14

·

Updated

2026-03-07

·

CVE-2026-28456

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.1.5 through 2026.2.13
Description The OpenClaw Gateway does not adequately limit configured hook module paths before passing them to the import() function, potentially allowing for code execution. An attacker with the ability to modify gateway configuration can load and execute unintended local modules within the Node.js process. This requires access to modify gateway configuration, which is considered a high privilege. The vulnerable component involves the import() function and the configuration parameters hooks.mappings[].transform.module and hooks.internal.handlers[].module.
Recommendations Upgrade to version 2026.2.14 or newer. Avoid exposing gateway configuration endpoints to untrusted networks. Review configuration for unsafe values in hooks.mappings[].transform.module and hooks.internal.handlers[].module.

Fix

Uncontrolled Search Path Element

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-06172
CVE-2026-28456
GHSA-V6C6-VQQG-W888

Affected Products

Openclaw