CVE-2026-28486 | OpenClaw up to 2026.2.13 Archive Extraction path traversal (GHSA-v892-hwpg-jwqp)
A vulnerability has been found in OpenClaw up to 2026.2.13 and classified as critical. This affects an unknown function of the component Archive Extraction Handler. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-28486. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.