PT-2026-23533 · Openclaw · Openclaw
222N5
·
Published
2026-02-14
·
Updated
2026-03-07
·
CVE-2026-28456
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.1.5 through 2026.2.13
Description
The OpenClaw Gateway does not adequately limit configured hook module paths before passing them to the
import() function, potentially allowing for code execution. An attacker with the ability to modify gateway configuration can load and execute unintended local modules within the Node.js process. This requires access to modify gateway configuration, which is considered a high privilege. The vulnerable component involves the import() function and the configuration parameters hooks.mappings[].transform.module and hooks.internal.handlers[].module.Recommendations
Upgrade to version 2026.2.14 or newer.
Avoid exposing gateway configuration endpoints to untrusted networks.
Review configuration for unsafe values in
hooks.mappings[].transform.module and hooks.internal.handlers[].module.Fix
Uncontrolled Search Path Element
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw