PT-2026-99175 · Openclaw · Openclaw

CVE-2026-100538

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openclaw versions prior to 2026.8.1
Description The software fails to apply the global or per-agent toolsBySender policy when processing outbound attachments. This allows a sender who has been denied filesystem read tools to trigger the reading of a known local file. The file contents are then disclosed to an admitted requester through a message attachment or a final-response media directive, even if the requester's agent turn did not include the read tool. Successful exploitation requires the attacker to know or derive a valid host path and utilize a delivery flow that accepts local attachments.
Recommendations Update to version 2026.8.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100538
GHSA-W5X7-C87M-3JPC

Affected Products

Openclaw