CVE-2026-45224: Openclaw Crabbox
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the intended /workspace directory. Attackers can craft a malicious .crabbox.yaml or crabbox.yaml file with traversal sequences to cause arbitrary file deletion and overwrite when sync.delete is enabled, as the workspace preparation logic executes rm -rf and mkdir -p operations on the resolved path without proper validation.
Affected products
- Openclaw Crabbox: before 0.9.0 (fixed in 0.9.0)
Published 2026-05-11. Last modified 2026-10-08.