PatchSiren cyber security CVE debrief
CVE-2026-100549 OpenClaw CVE debrief
CVE-2026-100549 is a path traversal vulnerability in OpenClaw versions before 2026.8.1, affecting QQBot voice attachment handling. Filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. This issue allows attackers to supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for OpenClaw deployments should assess exposure and prioritize verification and remediation. This includes OpenClaw administrators, security teams, and IT personnel responsible for maintaining and securing OpenClaw installations. Additionally, vulnerability management teams should review and update their vulnerability management processes to address this issue.
Why it matters
CVE-2026-100549 is a path traversal vulnerability in OpenClaw versions before 2026.8.1, affecting QQBot voice attachment handling. Defenders should prioritize verifying OpenClaw versions and restricting access to voice attachment handling.
- Verify OpenClaw version and upgrade to 2026.8.1 or later
- Restrict access to voice attachment handling
- Monitor for suspicious voice attachment activity
Technical summary
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling. Filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations. This vulnerability can be exploited by attackers to write files to arbitrary locations, potentially leading to code execution or data tampering. Defenders should prioritize verifying OpenClaw versions and restricting access to voice attachment handling.
Defensive priority
Defenders should prioritize verifying OpenClaw versions and restricting access to voice attachment handling.
Recommended defensive actions
- Verify OpenClaw version and upgrade to 2026.8.1 or later
- Restrict access to voice attachment handling
- Monitor for suspicious voice attachment activity
- Review OpenClaw configuration and ensure proper sanitization of filenames
- Implement additional logging and monitoring for voice attachment handling
- Conduct regular security audits to identify potential vulnerabilities
- Review and update incident response plans to address potential exploitation
Evidence notes
The CVE record and NVD entry provide details on the path traversal vulnerability in OpenClaw. However, the corpus does not establish versions, exploitation, impact, or remediation beyond vendor-provided information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100549 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100549
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100549 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100549
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-rm45-4jx5-2927
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-path-traversal-via-qqbot-voice-filenames
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.