CVE-2026-28486 is a path traversal vulnerability in OpenClaw versions 2026.1.16-2 prior to 2026.2.14, allowing attackers to write arbitrary files outside the intended directory during archive extraction for installation commands. This medium-severity vulnerability (CVSS 6.1) has a local attack vector with low complexity, requiring user interaction, and can lead to high integrity impact and low availability impact, enabling persistence or code execution. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2026.1.16-2, < 2026.2.14CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
>= 2026.1.20, < 2026.2.14CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
2026.1.16-2CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:2026.1.16-2:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.