CVE-2026-28459
HIGHOpenClaw <2026.2.12 - Path Traversal
Title source: llmDescription
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path outside the sessions directory to create files and append data repeatedly, potentially causing configuration corruption or denial of service.
Scores
CVSS v3
7.1
EPSS
0.0004
EPSS Percentile
12.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Classification
CWE
CWE-73
Status
published
Affected Products (2)
npm/openclaw
< 2026.2.12npm
openclaw/openclaw
< 2026.2.12
Timeline
Published
Mar 05, 2026
Tracked Since
Mar 06, 2026