OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resolution
CVE-2026-53813
7.3HIGH
What is CVE-2026-53813?
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from unintended local locations, potentially executing malicious code or accessing sensitive data.
Affected Version(s)
OpenClaw 0 < 2026.4.25
OpenClaw 2026.4.25
