CVE-2026-28393CRITICAL 9.8EPSS p34.9%

CVE-2026-28393CVE-2026-28393

Description

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration write access to load and execute malicious modules with gateway process privileges.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.44% probability of exploitation · percentile 34.9% · 2026-06-19T12:03:05Z
Published2026-03-05
Last modified2026-03-11

Underlying weaknesses· 1

CWE-22

References

  1. https://github.com/openclaw/openclaw/commit/18e8bd68c5015a894f999c6d5e6e32468965bfb5
  2. https://github.com/openclaw/openclaw/commit/a0361b8ba959e8506dc79d638b6e6a00d12887e4
  3. https://github.com/openclaw/openclaw/security/advisories/GHSA-7xhj-55q9-pc3m
  4. https://www.vulncheck.com/advisories/openclaw-beta-arbitrary-javascript-module-loading-via-hook-transform-path-traversal

1

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-28466
CVE
CVE-2026-22177
CVE
CVE-2026-28462
CVE
CVE-2026-29610
CVE
CVE-2026-32036
CVE
CVE-2026-32013
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.