PT-2026-99179 · Openclaw · Openclaw
CVE-2026-100542
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.5.28 through 2026.8.0
Description
The tar.bz2 skill installer mishandles archive listings by treating bounded command-output suffixes as complete listings. A specially crafted
.tar.bz2 or .tbz2 skill archive can push prohibited entries out of retained listings, allowing entry-count and size checks to pass. This enables the full extraction of the archive, bypassing extraction budgets. If an operator approves the installation of such an archive, it can result in the persistence of over-limit files or entry counts in the skill tools directory, leading to the consumption of disk space or inodes. This issue does not allow for the execution of archive contents.Recommendations
Update to version 2026.8.1.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw