CVE-2026-28456 | OpenClaw up to 2026.2.13 Gateway import uncontrolled search path (GHSA-v6c6-vqqg-w888)
A vulnerability labeled as problematic has been found in OpenClaw up to 2026.2.13. Affected by this issue is the function Import of the component Gateway. Such manipulation leads to uncontrolled search path.
This vulnerability is traded as CVE-2026-28456. An attack has to be approached locally. There is no exploit available.
The affected component should be upgraded.