CVE-2026-28484 | OpenClaw up to 2026.2.14 /git-hooks/pre-commit command injection (GHSA-mmpf-jwf4-h3qv)
A vulnerability, which was classified as critical, has been found in OpenClaw up to 2026.2.14. This vulnerability affects unknown code of the file /git-hooks/pre-commit. The manipulation leads to command injection.
This vulnerability is referenced as CVE-2026-28484. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.