OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named files beginning with dashes. The hook fails to use a -- separator when piping filenames through xargs to git add, enabling attackers to inject git flags and add sensitive ignored files like .env to git history.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 05 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named files beginning with dashes. The hook fails to use a -- separator when piping filenames through xargs to git add, enabling attackers to inject git flags and add sensitive ignored files like .env to git history. | |
| Title | OpenClaw 2026.2.15 - Option Injection in pre-commit Hook via Malicious Filenames | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T22:28:22.200Z
Reserved: 2026-02-27T19:21:05.169Z
Link: CVE-2026-28484
No data.
Status : Received
Published: 2026-03-05T22:16:23.213
Modified: 2026-03-05T22:16:23.213
Link: CVE-2026-28484
No data.
OpenCVE Enrichment
No data.
Weaknesses