CVE-2026-100526: Vulnerability in discord

Published Sep 26, 2026
·
Updated

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.

Affected Software

1 affected component
npm/@openclaw/discord<2026.9.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @openclaw/discord to a version that resolves this vulnerability.

    Fixed in 2026.9.3

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

OpenClaw deployments using @openclaw/discord before 2026.9.3 are exposed only where a sender is permitted to invoke the guild emoji or sticker upload actions. The sender must also know or be able to derive a useful local host path.

2

What can an attacker access through this flaw?

A permitted sender can cause bytes from a local file outside that sender's configured media roots to be included in an outbound emoji or sticker upload. The issue does not allow unrestricted filesystem browsing or code execution.

3

Is a default configuration known to be affected?

The available information does not state whether default configurations grant senders access to the guild asset actions. Exposure depends on whether those actions are available to the sender.

4

How can I remediate the issue?

Upgrade @openclaw/discord to version 2026.9.3. If an immediate upgrade is not possible, restrict access to the guild emoji and sticker upload actions for untrusted senders.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203