
CVE-2026-28456 OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook module paths before p… https://www.cve.org/CVERecord?id=CVE-2026-28456
Post summary
The post identifies CVE‑2026‑28456 affecting OpenClaw Gateway versions 2026.1.5 through 2026.2.13, noting insufficient path validation for hook modules, but provides no evidence of a PoC, exploit, active exploitation, or patch.
