CVE-2026-28486: OpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation Commands
OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allows arbitrary file writes outside the intended directory. Attackers can craft malicious archives that, when extracted via skills install, hooks install, plugins install, or signal install commands, write files to arbitrary locations enabling persistence or code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28486?
CVE-2026-28486 is considered a critical severity vulnerability due to its potential for arbitrary file writes.
How do I fix CVE-2026-28486?
To fix CVE-2026-28486, upgrade OpenClaw to version 2026.2.14 or later.
What types of software are affected by CVE-2026-28486?
CVE-2026-28486 affects OpenClaw versions prior to 2026.2.14.
What is the nature of the vulnerability in CVE-2026-28486?
CVE-2026-28486 is a path traversal vulnerability that allows attackers to extract files to unintended locations.
Can CVE-2026-28486 be exploited during installation commands?
Yes, CVE-2026-28486 can be exploited during archive extraction through installation commands.