CVE-2026-28456

HIGH

OpenClaw 2026.1.5-2026.2.14 - Code Injection

Title source: llm
STIX 2.1

Description

OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook module paths before passing them to dynamic import(), allowing code execution. An attacker with gateway configuration modification access can load and execute unintended local modules in the Node.js process.

Scores

CVSS v3 7.2
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
npm/openclaw 2026.1.5 - 2026.2.14npm
openclaw/openclaw 2026.1.5 - 2026.2.14
Published Mar 05, 2026
Tracked Since Mar 06, 2026