Executive brief
OpenClaw is a browser control and automation framework used for testing and monitoring web applications. A path traversal vulnerability in its API allows attackers with access to the browser control interface to write files outside OpenClaw's designated temporary directories, potentially overwriting or injecting arbitrary files on the system depending on process permissions.
Technical details
This is a path traversal vulnerability (CWE-22) in OpenClaw's browser control API that affects the POST /trace/stop, POST /wait/download, and POST /download endpoints. The root cause is inadequate validation of user-supplied output paths for trace and download files, which failed to consistently constrain writes to OpenClaw-managed temporary directories. An attacker with network access to the browser control API can supply crafted path traversal sequences (e.g., "../") to write output files outside intended temp roots. The fix constrains all three endpoints to enforce temp-root boundaries and reject traversal attempts. Versions prior to 2026.2.13 are affected; the fix was shipped in PR #15652 and merged on February 13, 2026.
Affected products
- OpenClaw OpenClaw < 2026.2.13
Timeline
- 2026-02-18: disclosed
- 2026-02-13: patched: Fix merged to main in PR #15652