CVE-2026-100533: OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
OpenClaw deployments before 2026.8.1 that use the tools.fs.workspaceOnly feature are affected. Exploitation is limited to admitted requesters.
What access does an attacker need?
An attacker needs network access and low-privileged access as an admitted requester. Exploitation also requires crafting paths involving canonically equivalent sibling directories and Unicode filename fallback behavior.
What data could be exposed?
The issue can allow an admitted requester to read files outside the configured workspace boundary. The provided information indicates confidentiality impact only; it does not indicate modification or availability impact.
How can I determine whether a deployment is affected?
Check whether OpenClaw is running a version earlier than 2026.8.1 and whether tools.fs.workspaceOnly is enabled or relied upon to constrain filesystem access. Review requests from admitted users for paths involving Unicode-normalized directory names or canonically equivalent sibling directories.