
CVE-2026-28479 OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecated and vulnerable… https://www.cve.org/CVERecord?id=CVE-2026-28479
Post summary
The passage states that OpenClaw versions before 2026.2.15 use deprecated SHA‑1 for sandbox identifier cache keys, rendering them vulnerable, and implies that upgrading to 2026.2.15 mitigates the risk.
