Path traversal in OpenClaw - CVE-2026-28462
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to write files outside intended temporary directories.
The vulnerability exists due to path traversal in the browser control API endpoints when handling user-supplied output paths for trace and download files. A remote attacker can send a specially crafted request to write files outside intended temporary directories.
Successful exploitation depends on the filesystem permissions of the OpenClaw process.