PT-2026-99184 · Npm · Openclaw

CVE-2026-100547

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.7.1 through 2026.7.2
Description OpenClaw, distributed as the npm package openclaw, contains an issue where alternate but valid file: URL spellings supplied over the Agent Client Protocol (ACP) are treated as relative paths. This causes the system to incorrectly classify these requests as reads scoped to the session working directory. If an operator connects openclaw acp client to an untrusted or compromised ACP peer, that peer can request a read of a file outside the session working directory without the required approval prompt, leading to the disclosure of local file contents. The impact is limited to file confidentiality, as mutating and command-capable tool classes are not affected.
Recommendations Update OpenClaw to version 2026.8.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100547
GHSA-356G-M7RX-7PM3

Affected Products

Openclaw