Sandbox skill mirroring path traversal could write outside the sandbox workspace
Fixed in: openclaw >= 2026.2.14
details
- Finding IDs
- F-OPENCLAW-001
- CVE
- CVE-2026-28457
- GHSA
- GHSA-xw4p-pw82-hqr7
- Status
- patched
- Fixed in
- openclaw >= 2026.2.14
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Sandbox skill mirroring path traversal could write outside the sandbox workspace
- Upstream CWE
- CWE-22
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
- CVE mapping note
- Recorded CVE and upstream metadata differ; upstream CVE: not assigned in this snapshot. The recorded mapping has not been changed.
F-OPENCLAW-001: File / path escapes. Mirroring resolves a path outside the intended directory. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-OPENCLAW-001
Security area (1seal assessment): Authorization. A skill name can escape the intended sandbox destination when files are mirrored. Reviewed 21 Sep 2026.