Path Traversal Vulnerability in OpenClaw by OpenClaw
CVE-2026-53846
7HIGH
What is CVE-2026-53846?
OpenClaw versions prior to 2026.4.29 have a path traversal issue in the install helper, allowing unauthorized access to the .env files in workspaces. This vulnerability enables attackers to manipulate the npm_execpath configuration, leading to the execution of unintended local package-manager executables during the dependency setup phase. Such actions can compromise the entire build environment, posing significant risks to application integrity and security.
Affected Version(s)
OpenClaw 0 < 2026.4.29
OpenClaw 2026.4.29
