PT-2026-23560 · Openclaw · Openclaw

Mark

·

Published

2026-02-14

·

Updated

2026-03-11

·

CVE-2026-28486

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.1.16-2 through 2026.2.13
Description A path traversal issue exists in archive extraction during installation commands. This allows a crafted archive to write files outside the intended extraction directory. The issue affects users who run installation commands against untrusted archives, such as those downloaded from a local file or URL. Specifically, the affected commands include openclaw skills install, openclaw hooks install, openclaw plugins install, and openclaw signal install. Successful exploitation can lead to arbitrary file write as the current user, potentially enabling persistence or code execution if an attacker can convince a user to install a malicious archive.
Recommendations Update to version 2026.2.14 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-06168
CVE-2026-28486
GHSA-V892-HWPG-JWQP

Affected Products

Openclaw