Executive brief
OpenClaw is a platform for managing AI skills and workflows. A path traversal vulnerability in its sandbox skill mirroring feature allows an attacker to write files outside the intended sandbox workspace directory. By crafting a malicious skill package with specially formatted names, an attacker can place files anywhere the OpenClaw process has permission to write, potentially overwriting critical configuration or application files.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in OpenClaw's sandbox skill mirroring functionality. When copying skills into the sandbox workspace, the application uses the skill's frontmatter name directly as part of the destination path without proper sanitization. An attacker who can provide a skill package (by controlling the SKILL.md frontmatter) can include traversal sequences like "../" or absolute paths to write files outside <sandbox_workspace>/skills/. The attack requires the victim to run OpenClaw with sandbox enabled and skill mirroring active, plus user interaction to process the malicious skill. The vulnerability affects all versions prior to 2026.2.14, which has been patched.
Affected products
- OpenClaw openclaw < 2026.2.14
Timeline
- 2026-03-02: disclosed: Advisory published
- 2026-02-14: patched: Fixed in version 2026.2.14