PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100538 OpenClaw CVE debrief

CVE-2026-100538 is a high-severity vulnerability in the OpenClaw npm package before version 2026.8.1. The issue allows a sender with explicitly denied filesystem read tools to cause a known local file to be read and returned via a final-response media directive or a message attachment, disclosing local file contents to an admitted requester. This requires knowledge or derivation of a useful host path and a delivery flow that accepts local attachments. The vulnerability is fixed in version 2026.8.1.

Vendor
OpenClaw
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders responsible for systems using OpenClaw for handling outbound attachments should assess exposure, especially those with untrusted or external senders. Security teams and administrators should prioritize updating OpenClaw to version 2026.8.1 or later to prevent local file disclosure.

Why it matters

CVE-2026-100538 is a high-severity vulnerability in OpenClaw that allows disclosure of local file contents. Defenders should prioritize updating to version 2026.8.1 or later and review systems for exposure, especially those with untrusted senders.

  • Potential disclosure of local file contents to untrusted parties
  • Bypass of security policies for filesystem read tools
  • Increased risk of sensitive information exposure
  • Need for verification of OpenClaw version and configuration

Technical summary

The OpenClaw npm package before version 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. This allows a sender with explicitly denied filesystem read tools to cause a known local file to be read and returned via a final-response media directive or a message attachment, disclosing local file contents to an admitted requester whose agent turn did not include the read tool. Exploitation requires knowledge or derivation of a useful host path and a delivery flow that accepts local attachments.

Defensive priority

Defenders should prioritize updating OpenClaw to version 2026.8.1 or later to prevent local file disclosure. Systems using OpenClaw for handling outbound attachments should be reviewed for exposure, especially those with untrusted or external senders. Verify that the update has been applied and test the configuration to ensure that the fix is effective.

Recommended defensive actions

  • Update OpenClaw to version 2026.8.1 or later
  • Review systems using OpenClaw for handling outbound attachments
  • Verify that the update has been applied and test the configuration
  • Perform a thorough review of system configurations for potential exposure
  • Implement additional monitoring to detect potential exploitation attempts
  • Conduct an asset inventory to identify all systems using OpenClaw
  • Establish a process for tracking and addressing exceptions

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, its impact, and the fix. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information, requiring verification from the supplied official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100538 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100538

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100538 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100538

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.