CVE-2026-53813

Severity CVSS v4.0:
HIGH
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
11/06/2026
Last modified:
12/06/2026

Description

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from unintended local locations, potentially executing malicious code or accessing sensitive data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* 2026.4.25 (excluding)