🚨 CVE-2026-100530
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects.
🎖@cveNotify
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects.
🎖@cveNotify
GitHub
Exec approvals could outlive their reviewed working directory
### Summary
Reusable exec approvals matched a command's arguments without binding the working directory. The same approved command could therefore run later in a different directory against fi...
Reusable exec approvals matched a command's arguments without binding the working directory. The same approved command could therefore run later in a different directory against fi...
🚨 CVE-2026-100531
The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization check fails open. An authenticated caller restricted to a single conversation who knows or obtains a file identifier can therefore download file contents from outside that conversation's scope, disclosing data across configured conversation boundaries. The issue does not allow listing arbitrary Slack files and does not bypass Slack authentication itself. The issue is fixed in version 2026.8.1.
🎖@cveNotify
The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization check fails open. An authenticated caller restricted to a single conversation who knows or obtains a file identifier can therefore download file contents from outside that conversation's scope, disclosing data across configured conversation boundaries. The issue does not allow listing arbitrary Slack files and does not bypass Slack authentication itself. The issue is fixed in version 2026.8.1.
🎖@cveNotify
GitHub
Slack file downloads could miss conversation authorization
### Summary
Slack `download-file` authorization could fail open when a file lacked the share metadata used to prove that it belonged to the requested conversation. A caller limited to one conversa...
Slack `download-file` authorization could fail open when a file lacked the share metadata used to prove that it belonged to the requested conversation. A caller limited to one conversa...
🚨 CVE-2026-100532
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and causing loss of availability; full account relinking additionally requires the attacker to scan the returned QR code with another phone. The issue affects the owner-only tool boundary rather than WhatsApp transport authentication. Fixed in 2026.8.1.
🎖@cveNotify
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and causing loss of availability; full account relinking additionally requires the attacker to scan the returned QR code with another phone. The issue affects the owner-only tool boundary rather than WhatsApp transport authentication. Fixed in 2026.8.1.
🎖@cveNotify
GitHub
WhatsApp login tool could reach non-owner turns
### Summary
The WhatsApp login tool could be exposed through the generic channel-tool path without preserving the originating sender's owner status. An admitted non-owner turn could request a ...
The WhatsApp login tool could be exposed through the generic channel-tool path without preserving the originating sender's owner status. An admitted non-owner turn could request a ...
🚨 CVE-2026-100533
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary.
🎖@cveNotify
GitHub
Unicode fallback could escape workspaceOnly roots
### Summary
When `tools.fs.workspaceOnly` was enabled, Unicode filename fallback could normalize already-validated parent directory components. On filesystems where canonically equivalent sibling ...
When `tools.fs.workspaceOnly` was enabled, Unicode filename fallback could normalize already-validated parent directory components. On filesystems where canonically equivalent sibling ...
🚨 CVE-2026-100534
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
🎖@cveNotify
GitHub
Webhook TaskFlow cancellation could target unrelated sessions
### Summary
A webhook TaskFlow route could accept and store an arbitrary child session key, then use that key during cancellation without confirming that the child belonged to the route's conf...
A webhook TaskFlow route could accept and store an arbitrary child session key, then use that key during cancellation without confirming that the child belonged to the route's conf...
🚨 CVE-2026-100535
OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to an unattended background (dreaming) agent holding broader file and command capabilities, allowing actions beyond the authority of the original turn and affecting files, commands, or services available to that agent. Exploitation requires the content to be captured, selected for later processing, and followed by the model. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to an unattended background (dreaming) agent holding broader file and command capabilities, allowing actions beyond the authority of the original turn and affecting files, commands, or services available to that agent. Exploitation requires the content to be captured, selected for later processing, and followed by the model. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Dreaming could widen restricted sender authority
### Summary
Session-derived memory could lose the originating requester's restrictions before later dreaming runs processed it. Text from an admitted sender with limited tools could be persist...
Session-derived memory could lose the originating requester's restrictions before later dreaming runs processed it. Text from an admitted sender with limited tools could be persist...
🚨 CVE-2026-100536
OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to read and send known host files that would otherwise be rejected.
🎖@cveNotify
OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to read and send known host files that would otherwise be rejected.
🎖@cveNotify
GitHub
Structured attachments could hide unvalidated host paths
### Summary
Structured message attachments accepted several equivalent source fields, but sandbox validation stopped after the first populated field. Telegram later processed every populated sourc...
Structured message attachments accepted several equivalent source fields, but sandbox validation stopped after the first populated field. Telegram later processed every populated sourc...
🚨 CVE-2026-100537
OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active Memory together with requester-specific tool rules, deterministic and hidden recall paths can retrieve durable memory and inject it into the agent's context even when toolsBySender explicitly denies that requester access to the memory tools (memory_search, memory_get). As a result, an admitted but denied sender can receive information derived from durable memory in the agent's response without directly invoking any memory tool. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active Memory together with requester-specific tool rules, deterministic and hidden recall paths can retrieve durable memory and inject it into the agent's context even when toolsBySender explicitly denies that requester access to the memory tools (memory_search, memory_get). As a result, an admitted but denied sender can receive information derived from durable memory in the agent's response without directly invoking any memory tool. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Active Memory recall could ignore requester policy
### Summary
Active Memory automatic recall could omit the originating requester's effective tool policy. Deterministic and hidden recall paths could retrieve and inject durable memory even whe...
Active Memory automatic recall could omit the originating requester's effective tool policy. Deterministic and hidden recall paths could retrieve and inject durable memory even whe...
🚨 CVE-2026-100538
OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a known local file to be read and returned via a final-response media directive or a message attachment, disclosing local file contents to an admitted requester whose agent turn did not include the read tool. Exploitation requires knowledge or derivation of a useful host path and a delivery flow that accepts local attachments. The issue is fixed in version 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a known local file to be read and returned via a final-response media directive or a message attachment, disclosing local file contents to an admitted requester whose agent turn did not include the read tool. Exploitation requires knowledge or derivation of a useful host path and a delivery flow that accepts local attachments. The issue is fixed in version 2026.8.1.
🎖@cveNotify
GitHub
Outbound attachments could ignore requester read denials
### Summary
Outbound attachment handling could read a local path without applying the originating sender's global or per-agent `toolsBySender` policy. A sender explicitly denied filesystem rea...
Outbound attachment handling could read a local path without applying the originating sender's global or per-agent `toolsBySender` policy. A sender explicitly denied filesystem rea...
🚨 CVE-2026-100539
OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at creation time because the execution-time resolver treats explicit disablement like an unavailable configuration snapshot and restores the stale authority. As a result, during an already-running agent turn the model can continue searching and reading durable memory after the operator revoked that access, for the remainder of that run. Exploitation requires memory to be disabled while a previously created memory tool remains active. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at creation time because the execution-time resolver treats explicit disablement like an unavailable configuration snapshot and restores the stale authority. As a result, during an already-running agent turn the model can continue searching and reading durable memory after the operator revoked that access, for the remainder of that run. Exploitation requires memory to be disabled while a previously created memory tool remains active. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Memory tools could retain revoked access
### Summary
Existing `memory_search` and `memory_get` tools could continue using an enabled configuration captured at creation after an operator hot-disabled memory. The execution-time resolver tr...
Existing `memory_search` and `memory_get` tools could continue using an enabled configuration captured at creation after an operator hot-disabled memory. The execution-time resolver tr...
🚨 CVE-2026-100540
OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity.
🎖@cveNotify
OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity.
🎖@cveNotify
GitHub
Feishu tools could use disabled default accounts
### Summary
Feishu model tools could select a configured default account without checking whether that account was disabled. In a multi-account setup, an enabled sibling could keep a tool family a...
Feishu model tools could select a configured default account without checking whether that account was disabled. In a multi-account setup, an enabled sibling could keep a tool family a...
🚨 CVE-2026-100541
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Matrix authorization could conflate case-distinct user IDs
### Summary
Matrix authorization lowercased complete user IDs, including historical localparts and the case-sensitive server-name portion. Distinct authenticated Matrix accounts could therefore no...
Matrix authorization lowercased complete user IDs, including historical localparts and the case-sensitive server-name portion. Distinct authenticated Matrix accounts could therefore no...
🚨 CVE-2026-100542
OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full. If an operator approves installation of such a malicious or compromised skill archive, over-limit files or entry counts are persisted in the skill tools directory, consuming disk space or inodes. The issue bypasses OpenClaw's extraction budgets but does not by itself execute archive contents. Fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full. If an operator approves installation of such a malicious or compromised skill archive, over-limit files or entry counts are persisted in the skill tools directory, consuming disk space or inodes. The issue bypasses OpenClaw's extraction budgets but does not by itself execute archive contents. Fixed in 2026.8.1.
🎖@cveNotify
GitHub
Truncated tar listings could bypass extraction limits
### Summary
The `tar.bz2` skill installer treated bounded command-output suffixes as complete archive listings. A crafted archive could push prohibited entries out of both retained listings, pass ...
The `tar.bz2` skill installer treated bounded command-output suffixes as complete archive listings. A crafted archive could push prohibited entries out of both retained listings, pass ...
🚨 CVE-2026-100543
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config.get) could test password candidates offline without going through the rate-limited Gateway authentication path. Recovering the password could grant the documented shared-secret operator authority. Secret references were not affected in the same way. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config.get) could test password candidates offline without going through the rate-limited Gateway authentication path. Recovering the password could grant the documented shared-secret operator authority. Secret references were not affected in the same way. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Config revision hashes could expose password verifiers
### Summary
Redacted configuration responses could include deterministic hashes computed over the original unredacted configuration. When a Gateway password had low entropy and the rest of the con...
Redacted configuration responses could include deterministic hashes computed over the original unredacted configuration. When a Gateway password had low entropy and the rest of the con...
🚨 CVE-2026-100544
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a deployment with inbound calling enabled can therefore drive tools intended for the trusted owner, potentially reading data, modifying files, executing commands, or controlling connected services depending on the agent's configuration. The issue is fixed in 2026.8.1.
🎖@cveNotify
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a deployment with inbound calling enabled can therefore drive tools intended for the trusted owner, potentially reading data, modifying files, executing commands, or controlling connected services depending on the agent's configuration. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Inbound voice calls could inherit owner tool authority
### Summary
Classic inbound voice calls could launch the configured agent without carrying the caller's identity or non-owner status. Owner-only filtering could therefore fail open and expose ...
Classic inbound voice calls could launch the configured agent without carrying the caller's identity or non-owner status. Owner-only filtering could therefore fail open and expose ...
🚨 CVE-2026-100546
OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participant after an asynchronous control check, causing a transcript to inherit another speaker's owner status. In Discord agent-proxy voice sessions using the affected realtime control path, an utterance from a non-owner participant could reach the downstream agent boundary marked as owner, so owner-sensitive behavior is applied to the wrong speaker. Exploitation depends on concurrent transcript timing and on the tools and commands available to the affected agent. The issue is fixed in 2026.9.2; as a workaround, disable Discord realtime voice for agents that distinguish owner and non-owner senders.
🎖@cveNotify
OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participant after an asynchronous control check, causing a transcript to inherit another speaker's owner status. In Discord agent-proxy voice sessions using the affected realtime control path, an utterance from a non-owner participant could reach the downstream agent boundary marked as owner, so owner-sensitive behavior is applied to the wrong speaker. Exploitation depends on concurrent transcript timing and on the tools and commands available to the affected agent. The issue is fixed in 2026.9.2; as a workaround, disable Discord realtime voice for agents that distinguish owner and non-owner senders.
🎖@cveNotify
GitHub
Discord realtime transcripts could inherit another speaker's owner status
### Summary
Discord realtime transcripts could inherit another speaker's owner status. In affected versions, concurrent control-classified voice transcripts could consume speaker context belon...
Discord realtime transcripts could inherit another speaker's owner status. In affected versions, concurrent control-classified voice transcripts could consume speaker context belon...
🚨 CVE-2026-100547
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly classified as reads scoped to the session working directory. When an operator connected `openclaw acp client` to an untrusted or compromised ACP peer, that peer could request a read of a file outside the session working directory without the approval prompt normally required for that path, resulting in disclosure of local file contents. The demonstrated impact is limited to file confidentiality; mutating and command-capable tool classes are not affected. This issue is fixed in OpenClaw 2026.8.1.
🎖@cveNotify
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly classified as reads scoped to the session working directory. When an operator connected `openclaw acp client` to an untrusted or compromised ACP peer, that peer could request a read of a file outside the session working directory without the approval prompt normally required for that path, resulting in disclosure of local file contents. The demonstrated impact is limited to file confidentiality; mutating and command-capable tool classes are not affected. This issue is fixed in OpenClaw 2026.8.1.
🎖@cveNotify
GitHub
ACP file URLs could skip out-of-cwd read approval
### Summary
ACP file URLs could skip out-of-cwd read approval. In affected versions, alternate but valid `file:` URL spellings were treated as relative paths and incorrectly classified as reads sc...
ACP file URLs could skip out-of-cwd read approval. In affected versions, alternate but valid `file:` URL spellings were treated as relative paths and incorrectly classified as reads sc...
🚨 CVE-2026-100548
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to a different fallback provider while still reusing the primary provider's configured API key, causing that credential to be transmitted as a bearer token to an unintended vendor. The practical impact depends on the configured providers, whether failover occurs, and the privileges attached to the primary provider key. The issue is fixed in 2026.8.1; as a workaround, disable cross-provider embedding fallback or configure each provider with separate, narrowly scoped credentials.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to a different fallback provider while still reusing the primary provider's configured API key, causing that credential to be transmitted as a bearer token to an unintended vendor. The practical impact depends on the configured providers, whether failover occurs, and the privileges attached to the primary provider key. The issue is fixed in 2026.8.1; as a workaround, disable cross-provider embedding fallback or configure each provider with separate, narrowly scoped credentials.
🎖@cveNotify
GitHub
Embedding fallback could forward a provider key across vendors
### Summary
Embedding fallback could forward a provider key across vendors. In affected versions, memory embedding failover could reuse the primary provider's configured API key while sending ...
Embedding fallback could forward a provider key across vendors. In affected versions, memory embedding failover could reuse the primary provider's configured API key while sending ...
🚨 CVE-2026-100549
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.
🎖@cveNotify
GitHub
QQBot voice filenames could escape the staging directory
### Summary
QQBot voice filenames could escape the staging directory. In affected versions, voice attachment filenames were decoded twice, allowing encoded traversal segments to reappear after fil...
QQBot voice filenames could escape the staging directory. In affected versions, voice attachment filenames were decoded twice, allowing encoded traversal segments to reappear after fil...
🚨 CVE-2026-100550
OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check, so a Teams member who is not on the allowlist can still trigger the configured agent despite the administrator's group boundary. The impact depends on the conversations, tools, and data available to that agent. The issue is fixed in version 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check, so a Teams member who is not on the allowlist can still trigger the configured agent despite the administrator's group boundary. The impact depends on the conversations, tools, and data available to that agent. The issue is fixed in version 2026.8.1.
🎖@cveNotify
GitHub
Microsoft Teams access-group failures could admit unlisted senders
### Summary
Microsoft Teams access-group failures could admit unlisted senders. In affected versions, missing or unsupported configured access groups produced denied results that were not rejected...
Microsoft Teams access-group failures could admit unlisted senders. In affected versions, missing or unsupported configured access groups produced denied results that were not rejected...
🚨 CVE-2026-100551
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.
🎖@cveNotify
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.
🎖@cveNotify
GitHub
iOS Control UI did not enforce saved Gateway TLS pins
### Summary
The iOS Control UI did not enforce saved Gateway TLS pins. In affected versions, authenticated Terminal and session Dashboard WebViews omitted the saved Gateway fingerprint even though...
The iOS Control UI did not enforce saved Gateway TLS pins. In affected versions, authenticated Terminal and session Dashboard WebViews omitted the saved Gateway fingerprint even though...