
CVE-2026-28457 OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmatter name paramete… https://www.cve.org/CVERecord?id=CVE-2026-28457
Post summary
CVE-2026-28457 is a path traversal vulnerability in OpenClaw’s sandbox skill mirroring feature, affecting all versions before 2026.2.14.
