CVE-2026-100564: OpenClaw before 2026.8.1 CSV Formula Injection via Attendance Export
OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute with spreadsheet user permissions when the export is opened in formula-enabled applications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
Organizations using OpenClaw versions before 2026.8.1 are exposed when they export attendance data to CSV and open that export in a formula-enabled spreadsheet application. The affected data field is the participant display name.
What must an attacker do to exploit it?
An attacker must be able to supply a participant display name containing spreadsheet formula characters. A user must then open an attendance CSV export containing that name in a formula-enabled spreadsheet application.
Are confidentiality, integrity, or availability affected?
The reported severity vector indicates low confidentiality and low integrity impact, with no availability impact. Formula execution occurs with the permissions of the spreadsheet user who opens the exported file.
How can I determine whether I am affected?
Check whether your OpenClaw deployment is running a version earlier than 2026.8.1 and whether attendance CSV exports are used. Review participant display names in exported CSV files for formula-like content or leading spreadsheet formula characters.