Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Fri, 06 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Fri, 06 Mar 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named files beginning with dashes. The hook fails to use a -- separator when piping filenames through xargs to git add, enabling attackers to inject git flags and add sensitive ignored files like .env to git history. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Title | OpenClaw 2026.2.15 - Option Injection in pre-commit Hook via Malicious Filenames | |
| CPEs | ||
| Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 05 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named files beginning with dashes. The hook fails to use a -- separator when piping filenames through xargs to git add, enabling attackers to inject git flags and add sensitive ignored files like .env to git history. | |
| Title | OpenClaw 2026.2.15 - Option Injection in pre-commit Hook via Malicious Filenames | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-03-06T16:45:23.712Z
Reserved: 2026-02-27T19:21:05.169Z
Link: CVE-2026-28484
No data.
Status : Rejected
Published: 2026-03-05T22:16:23.213
Modified: 2026-03-06T17:16:32.923
Link: CVE-2026-28484
No data.
OpenCVE Enrichment
Updated: 2026-03-06T14:59:50Z
No weakness.