CVE-2026-27001 | OpenClaw/Clawdbot/Moltbot up to 2026.2.14 Working Directory command injection (WID-SEC-2026-0459)
A vulnerability categorized as critical has been discovered in OpenClaw, Clawdbot and Moltbot up to 2026.2.14. This impacts an unknown function of the component Working Directory Handler. Executing a manipulation can lead to command injection.
This vulnerability is handled as CVE-2026-27001. It is possible to launch the attack on the local host. There is not any exploit available.
It is advisable to upgrade the affected component.