PT-2026-99184 · Npm · Openclaw
CVE-2026-100547
·
Published
2026-09-26
·
Updated
2026-09-26
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.7.1 through 2026.7.2
Description
OpenClaw, distributed as the npm package
openclaw, contains an issue where alternate but valid file: URL spellings supplied over the Agent Client Protocol (ACP) are treated as relative paths. This causes the system to incorrectly classify these requests as reads scoped to the session working directory. If an operator connects openclaw acp client to an untrusted or compromised ACP peer, that peer can request a read of a file outside the session working directory without the required approval prompt, leading to the disclosure of local file contents. The impact is limited to file confidentiality, as mutating and command-capable tool classes are not affected.Recommendations
Update OpenClaw to version 2026.8.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw