PatchSiren cyber security CVE debrief
CVE-2026-100545 OpenClaw CVE debrief
CVE-2026-100545 is a vulnerability in OpenClaw (npm package `openclaw`) before version 2026.8.1. The issue involves incorrect enforcement of sender tool policies during session-memory filename generation, which could lead to the invocation of tools outside a sender's effective policy. This vulnerability is considered medium severity with a CVSS score of 6. The issue is fixed in version 2026.8.1, and a workaround is to disable session-memory filename generation for agents reachable by lower-trust senders.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for OpenClaw deployments, particularly those with agents reachable by lower-trust senders, should assess exposure and prioritize patching or applying the workaround.
Why it matters
CVE-2026-100545 is a medium-severity vulnerability in OpenClaw that could allow unauthorized tool invocation and creation of persistent scheduled work. Defenders should prioritize patching to version 2026.8.1 or applying the workaround, and review sender tool policies and session-memory filename generation configuration.
- Potential unauthorized tool invocation
- Possible creation of persistent scheduled work
- Need to verify sender tool policies and session-memory filename generation configuration
- Requirement to patch or apply workaround to prevent exploitation
Technical summary
The OpenClaw (npm package `openclaw`) before version 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. This could allow model-mediated instructions to invoke tools outside a sender's effective policy, potentially leading to the creation of persistent scheduled work. The issue is fixed in version 2026.8.1. Defenders should prioritize patching to version 2026.8.1 or applying the workaround to disable session-memory filename generation for agents reachable by lower-trust senders. The demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes.
Defensive priority
Defenders should prioritize patching to version 2026.8.1 or applying the workaround to disable session-memory filename generation for agents reachable by lower-trust senders.
Recommended defensive actions
- Patch OpenClaw to version 2026.8.1
- Disable session-memory filename generation for agents reachable by lower-trust senders
- Review and update sender tool policies to prevent unauthorized tool invocation
- Verify OpenClaw deployments and assess exposure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source references provide details on the vulnerability, its impact, and the fix. However, there is limited information on exploitability and specific affected versions. Defenders should verify OpenClaw deployments, review sender tool policies, and assess exposure to prioritize patching or applying the workaround. The issue involves incorrect enforcement of sender tool policies during session-memory filename generation, potentially leading to unauthorized tool invocation and creation of persistent scheduled work.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100545 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100545
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100545 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100545
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-5fwv-rrvp-8xvr
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-policy-bypass-via-session-filename-generation
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.