CVE-2026-28391 | OpenClaw up to 2026.2.1 cmd.exe incomplete blacklist (GHSA-qj77-c3c8-9c3q)
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.2.1. This affects an unknown part of the file cmd.exe. Such manipulation leads to incomplete blacklist.
This vulnerability is traded as CVE-2026-28391. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.