CVE-2026-100545: OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation

Published Sep 26, 2026
·
Updated

OpenClaw (npm package openclaw) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating sender's policy had removed. When session-memory filename generation was enabled for an agent reachable by lower-trust senders, model-mediated instructions could cause the helper to invoke tools outside that sender's effective policy; the demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes. The issue is fixed in 2026.8.1; as a workaround, disable session-memory filename generation for agents reachable by lower-trust senders.

Affected Software

1 affected component
npm/openclaw<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/openclaw to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  2. Configuration

    Disable session-memory filename generation for agents reachable by lower-trust senders.

    OpenClaw session-memory filename generation = disabled

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Affected deployments are those running OpenClaw before 2026.8.1 with session-memory filename generation enabled on an agent that lower-trust senders can reach. Exposure also depends on the helper retaining tools that the sender's policy would otherwise remove.

2

What must an attacker be able to do to exploit it?

A lower-trust sender must be able to provide model-mediated instructions to a reachable agent. Successful exploitation additionally depends on the model acting on those instructions and on the tools exposed by the embedded filename-generation helper.

3

What can be done if upgrading is not immediately possible?

Disable session-memory filename generation for agents reachable by lower-trust senders. This prevents the vulnerable filename-generation path from being used.

4

What impact was demonstrated?

The demonstrated impact was creation of persistent scheduled work through tools that were outside the originating sender's effective policy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203