
CVE-2026-28459 OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary loc… https://www.cve.org/CVERecord?id=CVE-2026-28459
Post summary
OpenClaw before version 2026.2.12 has a path‑validation flaw that permits authenticated gateway clients to write transcript data to arbitrary locations.

