PT-2026-99273 · Clawhub · Clawhub
CVE-2026-100602
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClawHub versions prior to 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650
Description
The application backend contains a missing authorization check within the changelog preview feature. An authenticated user can trigger the
skills:generateChangelogPreview action for a skill they are not permitted to access. This allows the system to read the previous version of the skill without enforcing standard file-read authorization, potentially sending up to 8,000 characters of quarantined content to an AI provider and returning it in the preview, which leads to the disclosure of restricted skill content.Recommendations
Update to revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 or a later descendant.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clawhub