CVE-2026-27008

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated. In the admin-only `skills.install` flow, this could write files outside the intended install sandbox. Version 2026.2.15 contains a fix for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:26

Type Values Removed Values Added
Summary
  • (es) OpenClaw es un asistente personal de IA. Antes de la versión 2026.2.15, un error en la instalación de la habilidad 'download' permitía que los valores de 'targetDir' del frontmatter de la habilidad se resolvieran fuera del directorio de herramientas por habilidad si no se validaban estrictamente. En el flujo 'skills.install' solo para administradores, esto podría escribir archivos fuera del sandbox de instalación previsto. La versión 2026.2.15 contiene una solución para el problema.

20 Feb 2026, 18:01

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7
References () https://github.com/openclaw/openclaw/commit/2363e1b0853a028e47f90dcc1066e3e9809d65f1 - () https://github.com/openclaw/openclaw/commit/2363e1b0853a028e47f90dcc1066e3e9809d65f1 - Patch
References () https://github.com/openclaw/openclaw/commit/b6305e97256d67e439719faacf5af3de9727d6e1 - () https://github.com/openclaw/openclaw/commit/b6305e97256d67e439719faacf5af3de9727d6e1 - Patch
References () https://github.com/openclaw/openclaw/releases/tag/v2026.2.15 - () https://github.com/openclaw/openclaw/releases/tag/v2026.2.15 - Product, Release Notes
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-h7f7-89mm-pqh6 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-h7f7-89mm-pqh6 - Patch, Vendor Advisory

20 Feb 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 00:16

Updated : 2026-06-17 10:26


NVD link : CVE-2026-27008

Mitre link : CVE-2026-27008

CVE.ORG link : CVE-2026-27008


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-73

External Control of File Name or Path