HarborGuard / CVE
Back to search
HIGHCVE-2026-28393Published Modified CNA VulnCheck

CVE-2026-28393: OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration write access to load and execute malicious modules with gateway process privileges.

Metrics

CVSS v4.0
8.3
Severity
HIGH
Fixed in
2026.2.14
Affected Products
1

Fix available

2026.2.14
Affected packages
  • OpenClaw / OpenClaw
    < 2026.2.14 (from 2.0.0-beta3)
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N