PT-2026-23560 · Openclaw · Openclaw
Mark
·
Published
2026-02-14
·
Updated
2026-03-11
·
CVE-2026-28486
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.1.16-2 through 2026.2.13
Description
A path traversal issue exists in archive extraction during installation commands. This allows a crafted archive to write files outside the intended extraction directory. The issue affects users who run installation commands against untrusted archives, such as those downloaded from a local file or URL. Specifically, the affected commands include
openclaw skills install, openclaw hooks install, openclaw plugins install, and openclaw signal install. Successful exploitation can lead to arbitrary file write as the current user, potentially enabling persistence or code execution if an attacker can convince a user to install a malicious archive.Recommendations
Update to version 2026.2.14 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw