CVE-2026-28486

Source
https://cve.org/CVERecord?id=CVE-2026-28486
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28486.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-28486
Aliases
Published
2026-03-05T22:00:02Z
Modified
2026-08-12T03:51:16Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation Commands
Details

OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allows arbitrary file writes outside the intended directory. Attackers can craft malicious archives that, when extracted via skills install, hooks install, plugins install, or signal install commands, write files to arbitrary locations enabling persistence or code execution.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28486.json"
}
References

Affected packages

Git / github.com/openclaw/openclaw

Affected ranges

Type
GIT
Repo
https://github.com/openclaw/openclaw
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.1.16-2:*:*:*:*:node.js:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2026.1.20"
        },
        {
            "fixed": "2026.2.14"
        },
        {
            "introduced": "2026.1.16-2"
        },
        {
            "last_affected": "2026.1.16-2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

2026.*
2026.1.16-2
v2026.*
v2026.1.20
v2026.1.21
v2026.1.22
v2026.1.23
v2026.1.24
v2026.1.24-1
v2026.1.29
v2026.1.30
v2026.2.1
v2026.2.12
v2026.2.13
v2026.2.2
v2026.2.3
v2026.2.6
v2026.2.6-1
v2026.2.6-2
v2026.2.6-3
v2026.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28486.json"