PT-2026-49763 · Openclaw · Openclaw

·

CVE-2026-53846

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.29
Description A path traversal issue exists in the install helper where workspace .env files can override the npm execpath configuration used for bundled runtime dependency installation. This allows an attacker with workspace access to execute unintended local package-manager executables during dependency setup, potentially compromising the build environment.
Recommendations Update to version 2026.4.29. Install bundled runtime dependencies only from trusted workspaces. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the install helper feature when it is not needed.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53846
GHSA-24VR-RPRV-67RF
GHSA-QP5J-JR73-M2PW

Affected Products

Openclaw