CVE-2026-100547: OpenClaw before 2026.8.1 Authentication Bypass via File URL

Published Sep 26, 2026
·
Updated

OpenClaw is a coding agent distributed as the npm package openclaw. In affected versions (2026.7.1 through 2026.7.2), alternate but valid file: URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly classified as reads scoped to the session working directory. When an operator connected openclaw acp client to an untrusted or compromised ACP peer, that peer could request a read of a file outside the session working directory without the approval prompt normally required for that path, resulting in disclosure of local file contents. The demonstrated impact is limited to file confidentiality; mutating and command-capable tool classes are not affected. This issue is fixed in OpenClaw 2026.8.1.

Affected Software

1 affected component
npm/openclaw>=2026.7.1<=2026.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/openclaw to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Operators using OpenClaw versions 2026.7.1 through 2026.7.2 who connect the `openclaw acp client` to an untrusted or compromised ACP peer are exposed. The peer can cause local files outside the session working directory to be read without the normal approval prompt.

2

What does an attacker need to exploit it?

An attacker needs to control or compromise an ACP peer that an operator connects to with `openclaw acp client`. Exploitation also relies on the peer supplying alternate but valid `file:` URL spellings over ACP.

3

Are command execution or file modification capabilities affected?

No. The demonstrated impact is limited to disclosure of local file contents; mutating and command-capable tool classes are not affected.

4

What should be done if an immediate upgrade is not possible?

Do not connect `openclaw acp client` to untrusted ACP peers, and treat potentially compromised peers as untrusted. This prevents those peers from issuing the crafted file-read requests described in the advisory.

5

Which version fixes the issue?

OpenClaw 2026.8.1 fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203