CVE-2026-28484
Severity CVSS v4.0:
CRITICAL
Type:
CWE-77
Command Injection
Publication date:
05/03/2026
Last modified:
06/03/2026
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/openclaw/openclaw/commit/b88f37762f5b6d7ec0f589eb761815e466e4ef4b
- https://github.com/openclaw/openclaw/commit/ba84b1253967143692166023f9e174c149b6f2ed
- https://github.com/openclaw/openclaw/security/advisories/GHSA-mmpf-jwf4-h3qv
- https://www.vulncheck.com/advisories/openclaw-option-injection-in-pre-commit-hook-via-malicious-filenames



