PT-2026-99179 · Openclaw · Openclaw

CVE-2026-100542

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.5.28 through 2026.8.0
Description The tar.bz2 skill installer mishandles archive listings by treating bounded command-output suffixes as complete listings. A specially crafted .tar.bz2 or .tbz2 skill archive can push prohibited entries out of retained listings, allowing entry-count and size checks to pass. This enables the full extraction of the archive, bypassing extraction budgets. If an operator approves the installation of such an archive, it can result in the persistence of over-limit files or entry counts in the skill tools directory, leading to the consumption of disk space or inodes. This issue does not allow for the execution of archive contents.
Recommendations Update to version 2026.8.1.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100542
GHSA-6XPV-WWR5-265H

Affected Products

Openclaw