OpenClaw browser download helpers accepted an unsanitized output path. When invoked via the browser control gateway routes, this allowed path traversal to write downloads outside the intended OpenClaw temp downloads directory.
This issue is not exposed via the AI agent tool schema (no download action). Exploitation requires authenticated CLI access or an authenticated gateway RPC token.
openclaw (npm)Affected code: src/browser/pw-tools-core.downloads.ts (waitForDownloadViaPlaywright, downloadViaPlaywright).
Fixed entrypoints (as of 2026.2.13):
/wait/download and /download now restrict path to DEFAULT_DOWNLOAD_DIR via resolvePathWithinRoot.Upgrade to openclaw >=2026.2.13.
Thanks @locus-x64 for reporting.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-18T17:37:52Z",
"nvd_published_at": "2026-02-20T00:16:16Z",
"severity": "MODERATE"
}