PT-2026-99273 · Clawhub · Clawhub

CVE-2026-100602

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClawHub versions prior to 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650
Description The application backend contains a missing authorization check within the changelog preview feature. An authenticated user can trigger the skills:generateChangelogPreview action for a skill they are not permitted to access. This allows the system to read the previous version of the skill without enforcing standard file-read authorization, potentially sending up to 8,000 characters of quarantined content to an AI provider and returning it in the preview, which leads to the disclosure of restricted skill content.
Recommendations Update to revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 or a later descendant.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100602
GHSA-G3JP-JJ55-JRCR

Affected Products

Clawhub