OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global...
zetlyn/cve-ghsa vulnerability ghsa GHSA-m2g4-5ff5-4cf5 cve CVE-2026-100538 known 2026-09-26
https://github.com/advisories/GHSA-m2g4-5ff5-4cf5
Properties
| cvss | 6.5receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
|---|---|
| cwe | CWE-863receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
| severity | high From 7.0 to 8.9. receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
Text
OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global...
OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a known local file to be read and returned via a final-response media directive or a message attachment, disclosing local file contents to an admitted requester whose agent turn did not include the read tool. Exploitation requires knowledge or derivation of a useful host path and a delivery flow that accepts local attachments. The issue is fixed in version 2026.8.1.