PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100537 OpenClaw CVE debrief

CVE-2026-100537 is a vulnerability in the OpenClaw npm package before version 2026.8.1. It fails to apply the originating requester's effective tool policy during Active Memory automatic recall, potentially allowing admitted but denied senders to receive information derived from durable memory. The issue is fixed in version 2026.8.1. This vulnerability can lead to information disclosure and has a low severity. Defenders and administrators using OpenClaw with Active Memory and requester-specific tool rules should assess their exposure and prioritize upgrading to version 2026.8.1 or later.

Vendor
OpenClaw
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders and administrators using OpenClaw with Active Memory and requester-specific tool rules should assess their exposure and prioritize upgrading to version 2026.8.1 or later.

Why it matters

CVE-2026-100537 is a low-severity vulnerability in OpenClaw that can lead to information disclosure. Defenders should prioritize verifying and upgrading to version 2026.8.1 or later, especially in deployments using Active Memory with requester-specific tool rules.

  • Potential information disclosure via durable memory
  • Need to verify and update OpenClaw version
  • Possible impact on Active Memory configurations
  • Requires review of requester-specific tool rules

Technical summary

The OpenClaw npm package before version 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. This can lead to deterministic and hidden recall paths retrieving durable memory and injecting it into the agent's context, potentially allowing admitted but denied senders to receive information derived from durable memory. The vulnerability has a low severity and is fixed in version 2026.8.1. Defenders should prioritize verifying and upgrading to OpenClaw version 2026.8.1 or later, especially in deployments using Active Memory with requester-specific tool rules.

Defensive priority

Defenders should prioritize verifying and upgrading to OpenClaw version 2026.8.1 or later, especially in deployments using Active Memory with requester-specific tool rules.

Recommended defensive actions

  • Verify OpenClaw version and upgrade to 2026.8.1 or later if necessary
  • Review and update Active Memory configurations and requester-specific tool rules
  • Monitor for potential information disclosure via durable memory
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability details are based on the CVE Program record and the NVD vulnerability detail page. Additional information is available from source references, including GitHub and Vulncheck advisories.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100537 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100537

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100537 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100537

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.