PT-2026-49763 · Openclaw · Openclaw

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53846

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can execute unintended local package-manager executables during dependency setup to compromise the build environment.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2026-53846

Affected Products

Openclaw