openclaw (npm)<= 2026.2.142026.2.15A bug in download skill installation allowed targetDir values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated.
In the admin-only skills.install flow, this could write files outside the intended install sandbox.
Thanks @Adam55A-code for reporting.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-18T22:44:18Z",
"nvd_published_at": "2026-02-20T00:16:17Z"
}