Description

OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. When invoked via the browser control gateway routes, this allowed path traversal to write downloads outside the intended OpenClaw temp downloads directory. This issue is not exposed via the AI agent tool schema (no `download` action). Exploitation requires authenticated CLI access or an authenticated gateway RPC token. Version 2026.2.13 fixes the issue.

INFO

Published Date :

2026-02-19T23:08:44.670Z

Last Modified :

2026-02-20T15:38:25.996Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-26972 vulnerability.

Vendors Products
Openclaw
  • Openclaw

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact