CVE-2026-28459

OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path outside the sessions directory to create files and append data repeatedly, potentially causing configuration corruption or denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-03-05 22:16

Updated : 2026-03-09 17:39


NVD link : CVE-2026-28459

Mitre link : CVE-2026-28459

CVE.ORG link : CVE-2026-28459


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-73

External Control of File Name or Path