CVE-2026-28457: OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmatter name parameter unsanitized when copying skills into the sandbox workspace. Attackers who provide a crafted skill package with traversal sequences like ../ or absolute paths in the name field can write files outside the sandbox workspace root directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28457?
CVE-2026-28457 is classified as a medium severity vulnerability due to its potential for exploitation through path traversal.
How do I fix CVE-2026-28457?
To mitigate CVE-2026-28457, upgrade OpenClaw to version 2026.2.14 or higher where the vulnerability has been patched.
What is the impact of CVE-2026-28457?
The impact of CVE-2026-28457 allows attackers to read arbitrary files on the server through the sandbox skill mirroring feature.
Which versions of OpenClaw are affected by CVE-2026-28457?
OpenClaw versions prior to 2026.2.14 are affected by CVE-2026-28457.
Is sandbox skill mirroring related to CVE-2026-28457?
Yes, CVE-2026-28457 specifically involves a path traversal vulnerability in the sandbox skill mirroring feature.