PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100545 OpenClaw CVE debrief

CVE-2026-100545 is a vulnerability in OpenClaw (npm package `openclaw`) before version 2026.8.1. The issue involves incorrect enforcement of sender tool policies during session-memory filename generation, which could lead to the invocation of tools outside a sender's effective policy. This vulnerability is considered medium severity with a CVSS score of 6. The issue is fixed in version 2026.8.1, and a workaround is to disable session-memory filename generation for agents reachable by lower-trust senders.

Vendor
OpenClaw
Product
Unknown
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders responsible for OpenClaw deployments, particularly those with agents reachable by lower-trust senders, should assess exposure and prioritize patching or applying the workaround.

Why it matters

CVE-2026-100545 is a medium-severity vulnerability in OpenClaw that could allow unauthorized tool invocation and creation of persistent scheduled work. Defenders should prioritize patching to version 2026.8.1 or applying the workaround, and review sender tool policies and session-memory filename generation configuration.

  • Potential unauthorized tool invocation
  • Possible creation of persistent scheduled work
  • Need to verify sender tool policies and session-memory filename generation configuration
  • Requirement to patch or apply workaround to prevent exploitation

Technical summary

The OpenClaw (npm package `openclaw`) before version 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. This could allow model-mediated instructions to invoke tools outside a sender's effective policy, potentially leading to the creation of persistent scheduled work. The issue is fixed in version 2026.8.1. Defenders should prioritize patching to version 2026.8.1 or applying the workaround to disable session-memory filename generation for agents reachable by lower-trust senders. The demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes.

Defensive priority

Defenders should prioritize patching to version 2026.8.1 or applying the workaround to disable session-memory filename generation for agents reachable by lower-trust senders.

Recommended defensive actions

  • Patch OpenClaw to version 2026.8.1
  • Disable session-memory filename generation for agents reachable by lower-trust senders
  • Review and update sender tool policies to prevent unauthorized tool invocation
  • Verify OpenClaw deployments and assess exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source references provide details on the vulnerability, its impact, and the fix. However, there is limited information on exploitability and specific affected versions. Defenders should verify OpenClaw deployments, review sender tool policies, and assess exposure to prioritize patching or applying the workaround. The issue involves incorrect enforcement of sender tool policies during session-memory filename generation, potentially leading to unauthorized tool invocation and creation of persistent scheduled work.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100545 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100545

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100545 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100545

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.