PT-2026-23534 · Openclaw · Openclaw
Oleh Konko
·
Published
2026-03-02
·
Updated
2026-03-07
·
CVE-2026-28457
CVSS v3.1
7.9
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.14
Description
The software contains a path traversal issue in sandbox skill mirroring when the skill frontmatter
name parameter is used without proper sanitization during skill copying into the sandbox workspace. An attacker can provide a specially crafted skill package with traversal sequences, such as '../' or absolute paths, within the name field to write files outside the designated sandbox workspace root directory. This could allow writing files within the permissions of the user running OpenClaw. The issue requires the attacker to provide a skill package and the victim to have sandbox mode enabled with skill mirroring active.Recommendations
Update to version 2026.2.14 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw