CVE-2026-28447

HIGH

OpenClaw 2026.1.29-beta.1-2026.2.1 - Path Traversal

Title source: llm
STIX 2.1

Description

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin package names to escape the extensions directory. Attackers can craft scoped package names containing path traversal sequences like .. to write files outside the intended installation directory when victims run the plugins install command.

Scores

CVSS v3 8.1
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
npm/openclaw 2026.1.20 - 2026.2.1npm
openclaw/openclaw 2026.1.29 - 2026.2.1
Published Mar 05, 2026
Tracked Since Mar 06, 2026