CVE-2026-28457 | OpenClaw up to 2026.2.13 Skill path traversal (GHSA-xw4p-pw82-hqr7)
A vulnerability labeled as critical has been found in OpenClaw up to 2026.2.13. This impacts an unknown function of the component Skill Handler. The manipulation results in path traversal.
This vulnerability is known as CVE-2026-28457. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.