CVE-2026-28393

Severity CVSS v4.0:
HIGH
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
05/03/2026
Last modified:
06/03/2026

Description

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration write access to load and execute malicious modules with gateway process privileges.