CVE-2026-27008 | OpenClaw/Clawdbot/Moltbot up to 2026.2.14 Skill Installation targetDir file inclusion (WID-SEC-2026-0459)
A vulnerability has been found in OpenClaw, Clawdbot and Moltbot up to 2026.2.14 and classified as problematic. This issue affects some unknown processing of the component Skill Installation Handler. The manipulation of the argument targetDir leads to file inclusion.
This vulnerability is documented as CVE-2026-27008. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.