CVE-2026-53865: Openclaw
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operator-unintended paths during maintenance operations by manipulating workspace-derived environment paths.
Affected products
- Openclaw Openclaw: before 2026.5.26 (fixed in 2026.5.26); version 2026.5.26 only
Published 2026-06-16. Last modified 2026-06-18.