OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operator-unintended paths during maintenance operations by manipulating workspace-derived environment paths.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | npm/openclaw: < 2026.5.2 |
Updated affected versions to include 2026.5.1, changed severity to MEDIUM, and noted that no exploit is available.
Initial creation