Junglewise Threat Intelligence

CVE-2026-28453: OpenClaw path traversal in tar archive extraction

CVE-2026-28453 · Severity: low · CVSS 3.1 · Published 2026-03-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a plugin and hook management tool that allows users to install custom extensions via tar archives. A path traversal vulnerability in the archive extraction code allows an attacker to write files outside the intended directory when a user installs a malicious archive, potentially leading to configuration tampering or arbitrary code execution.

Technical details

The vulnerability is a classic Zip Slip path traversal flaw (CWE-22) in the extractArchive() function of src/infra/archive.ts. Versions prior to 2026.2.14 use tar.x({ cwd: destDir }) without validating or sanitizing entry paths, allowing sequences like ../../ to escape the destination directory. The vulnerability affects plugin and hook installation flows. Exploitation requires a user to manually install a crafted .tar/.tgz file, but once triggered, an attacker can write arbitrary files within the OpenClaw process permissions, potentially achieving code execution. The fix is available in version 2026.2.14.

Affected products

  • OpenClaw OpenClaw < 2026.2.14

Timeline

  • 2026-03-02: disclosed
  • 2026-02-16: patched: Fix available in version 2026.2.14

References

Related threats