CVE-2026-28486

MEDIUM6.1EPSS 0.05%

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

發布日:2026/3/2修改日:2026/3/6

描述

## Summary A path traversal (Zip Slip) issue in archive extraction during explicit installation commands could allow a crafted archive to write files outside the intended extraction directory. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `>=2026.1.16-2 <2026.2.14` - Fixed version: `2026.2.14` ## Affected Commands / Flows This only affects users who run installation commands against an untrusted archive (local file or download URL), for example: - `openclaw skills install` (download+extract installers) - `openclaw hooks install` (archive installs) - `openclaw plugins install` (archive installs) - `openclaw signal install` (signal-cli asset extraction) It is not triggered by receiving messages or normal gateway operation. ## Impact Arbitrary file write as the current user. In the worst case this can be used for persistence or code execution if an attacker can convince a user to install a crafted archive. ## Fix - Fix commit: `3aa94afcfd12104c683c9cad81faf434d0dadf87` - Released in: `2026.2.14` ## Credits OpenClaw thanks @markmusson for reporting.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

參考連結(5)