CVE-2026-28462: OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output Paths
OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and download files without consistently constraining writes to temporary directories. Attackers with API access can exploit path traversal in POST /trace/stop, POST /wait/download, and POST /download endpoints to write files outside intended temp roots.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28462?
CVE-2026-28462 has been assigned a medium severity rating due to the potential for path traversal vulnerabilities.
How do I fix CVE-2026-28462?
To mitigate CVE-2026-28462, upgrade OpenClaw to version 2026.2.13 or later.
What kind of exploitation is possible with CVE-2026-28462?
CVE-2026-28462 can be exploited to conduct path traversal attacks, allowing unauthorized access to file system locations.
Which versions of OpenClaw are affected by CVE-2026-28462?
OpenClaw versions prior to 2026.2.13 are affected by CVE-2026-28462.
Is there a workaround for CVE-2026-28462 until I can update?
There are no recommended workarounds for CVE-2026-28462; upgrading to the latest version is the best course of action.