CVE-2026-28393
EUVD-2026-989305.03.2026, 22:16
OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration write access to load and execute malicious modules with gateway process privileges.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openclaw | openclaw | 2026.1.4 ≤ 𝑥 < 2026.2.14 |
| openclaw | openclaw | 2.0.0:beta3 |
| openclaw | openclaw | 2.0.0:beta4 |
| openclaw | openclaw | 2.0.0:beta5 |
𝑥
= Vulnerable software versions
References