CVE-2026-28393 | OpenClaw up to 2026.2.13 Hook Transform hooks.mappings[].transform.module uncontrolled search path (GHSA-7xhj-55q9-pc3m)
A vulnerability was found in OpenClaw up to 2026.2.13. It has been rated as problematic. This affects an unknown part of the component Hook Transform Module. The manipulation of the argument hooks.mappings[].transform.module leads to uncontrolled search path.
This vulnerability is uniquely identified as CVE-2026-28393. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.