CVE-2026-28463 | OpenClaw up to 2026.2.13 Authorized Call os command injection (GHSA-xvhf-x56f-2hpp)
A vulnerability marked as critical has been reported in OpenClaw up to 2026.2.13. This affects an unknown part of the component Authorized Call Handler. Performing a manipulation results in os command injection.
This vulnerability is known as CVE-2026-28463. Attacking locally is a requirement. No exploit is available.
It is suggested to upgrade the affected component.