PT-2026-99163 · Unknown · @Openclaw/Discord
CVE-2026-100526
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@openclaw/discord versions prior to 2026.9.3
Description
The Discord integration for OpenClaw fails to maintain the sender-scoped media policy during emoji and sticker upload actions before a local file is loaded. An authorized sender can bypass configured media root restrictions to read a host path and include bytes from an out-of-policy local file in an outbound upload. This requires access to the guild asset action and knowledge of a valid local path. This issue does not allow for code execution or unrestricted filesystem browsing.
Recommendations
Update @openclaw/discord to version 2026.9.3.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Openclaw/Discord