Path traversal in OpenClaw - CVE-2026-28447
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to write files outside the intended extensions directory.
The vulnerability exists due to path traversal in the plugin installation directory handling when processing attacker-controlled plugin content during plugin installation. A remote attacker can supply a specially crafted plugin package name to write files outside the intended extensions directory.
User interaction is required to run openclaw plugins install on attacker-controlled plugin content.