CVE-2026-28462 | OpenClaw up to 2026.2.12 Browser Control API /trace/stop path traversal (GHSA-gq9c-wg68-gwj2)
A vulnerability marked as critical has been reported in OpenClaw up to 2026.2.12. Affected is an unknown function of the file /trace/stop of the component Browser Control API. This manipulation causes path traversal.
This vulnerability is handled as CVE-2026-28462. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.