PT-2026-23534 · Openclaw · Openclaw

Oleh Konko

·

Published

2026-03-02

·

Updated

2026-03-07

·

CVE-2026-28457

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The software contains a path traversal issue in sandbox skill mirroring when the skill frontmatter name parameter is used without proper sanitization during skill copying into the sandbox workspace. An attacker can provide a specially crafted skill package with traversal sequences, such as '../' or absolute paths, within the name field to write files outside the designated sandbox workspace root directory. This could allow writing files within the permissions of the user running OpenClaw. The issue requires the attacker to provide a skill package and the victim to have sandbox mode enabled with skill mirroring active.
Recommendations Update to version 2026.2.14 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-28457
GHSA-XW4P-PW82-HQR7

Affected Products

Openclaw