MEDIUM
OpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation Commands
Published Mar 5, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.20%
Description
OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allows arbitrary file writes outside the intended directory. Attackers can craft malicious archives that, when extracted via skills install, hooks install, plugins install, or signal install commands, write files to arbitrary locations enabling persistence or code execution.
Affected products
-
- Version 2026.1.16-2StatusaffectedConstraints<2026.2.14
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 2026.1.16-2 Fixed 2026.2.14
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 2026.1.16-2 | 2026.2.14 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-v892-hwpg-jwqp Advisory
- https://github.com/openclaw/openclaw/commit/3aa94afcfd12104c683c9cad81faf434d0dadf87 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-v892-hwpg-jwqp vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28486
- https://www.vulncheck.com/advisories/openclaw-path-traversal-zip-slip-in-archive-extraction-via-installation-commands third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-v892-hwpg-jwqp | Advisory | |
| https://github.com/openclaw/openclaw/commit/3aa94afcfd12104c683c9cad81faf434d0dadf87 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-v892-hwpg-jwqp | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-28486 | ||
| https://www.vulncheck.com/advisories/openclaw-path-traversal-zip-slip-in-archive-extraction-via-installation-commands | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 5, 2026
Updated Mar 9, 2026
Reserved Feb 27, 2026
Link CVE-2026-28486
CISA Vulnrichment
GHSA-V892-HWPG-JWQP Updated Mar 9, 2026