- CVE-2026-100520 HIGH CVSS 8.7 -
NVD: Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. NVD: Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants. OSV: Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint
An attacker may be able to reach files outside the intended application path; CVSS 8.7 (HIGH); EPSS percentile 59; sources: NVD, OSV.
- CVE-2026-100530 HIGH CVSS 8.5 -
NVD: OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. NVD: Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects. OSV: OpenClaw before 2026.8.1 Exec Approval Directory Binding
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.5 (HIGH); EPSS percentile 7; sources: NVD, OSV.
- CVE-2026-100535 HIGH CVSS 7.7 -
NVD: OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. NVD: In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to an unattended background (dreaming) agent holding broader... NVD: Exploitation requires the content to be captured, selected for later processing, and followed by the model.
An attacker may cross a privilege boundary and gain more access than intended; CVSS 7.7 (HIGH); EPSS percentile 17; sources: NVD, OSV.
- CVE-2026-100529 HIGH CVSS 7.4 -
NVD: OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. NVD: Attackers can exploit glob metacharacter interpretation and node display name reuse to access sibling paths or different nodes beyond the operator's original approval scope. OSV: OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.4 (HIGH); EPSS percentile 9; sources: NVD, OSV.
- CVE-2026-100504 HIGH CVSS 7.3 -
NVD: Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. NVD: Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution. OSV: Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 7.3 (HIGH); EPSS percentile 2; sources: NVD, OSV.
- CVE-2026-100532 HIGH CVSS 7.2 -
NVD: @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. NVD: An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and causing loss of availability; full account relinking additionally requires the... NVD: The issue affects the owner-only tool boundary rather than WhatsApp transport authentication.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 7.2 (HIGH); EPSS percentile 17; sources: NVD, OSV.
- CVE-2026-100536 HIGH CVSS 7.1 -
NVD: OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. NVD: Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to read and send known host files that would otherwise be rejected. OSV: OpenClaw before 2026.8.1 Path Traversal via Structured Attachments
An attacker may be able to reach files outside the intended application path; CVSS 7.1 (HIGH); EPSS percentile 35; sources: NVD, OSV.
- CVE-2026-100531 HIGH CVSS 7.1 -
NVD: The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization check fails open. NVD: An authenticated caller restricted to a single conversation who knows or obtains a file identifier can therefore download file contents from outside that conversation's scope, disclosing data across configured conversation boundaries. NVD: The issue does not allow listing arbitrary Slack files and does not bypass Slack authentication itself.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.1 (HIGH); EPSS percentile 24; sources: NVD, OSV.
- CVE-2026-100527 MEDIUM CVSS 6.9 -
NVD: OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. NVD: Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2. OSV: OpenClaw before 2026.8.2 Denial of Service via Browser Relay
The affected service may become unavailable or unreliable; CVSS 6.9 (MEDIUM); EPSS percentile 26; sources: NVD, OSV.
- CVE-2026-100533 MEDIUM CVSS 6.0 -
NVD: OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. NVD: Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary. OSV: OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback
An attacker may be able to reach files outside the intended application path; CVSS 6.0 (MEDIUM); EPSS percentile 20; sources: NVD, OSV.
- CVE-2026-100526 MEDIUM CVSS 6.0 -
NVD: OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. NVD: A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. NVD: Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.0 (MEDIUM); EPSS percentile 19; sources: NVD, OSV.
- CVE-2026-100528 MEDIUM CVSS 5.9 -
NVD: OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. NVD: In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the... NVD: A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.9 (MEDIUM); EPSS percentile 14; sources: NVD, OSV.
- CVE-2026-100525 MEDIUM CVSS 5.3 -
NVD: The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. NVD: In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read scope can retrieve the diagnostics document even though ordinary read methods reject the same identity, disclosing... NVD: Shared-secret Gateway callers already hold the documented full operator scope and are not affected.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 5.3 (MEDIUM); EPSS percentile 14; sources: NVD, OSV.
- CVE-2026-100524 MEDIUM CVSS 5.3 -
NVD: Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. NVD: Attackers can craft links or embed images to force administrators to install, update, pause, or unpause extensions by tricking them into visiting a malicious page while authenticated. OSV: Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.3 (MEDIUM); EPSS percentile 2; sources: NVD, OSV.
- CVE-2026-100522 MEDIUM CVSS 5.1 -
NVD: Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. NVD: Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to execute arbitrary JavaScript in victim browser sessions. OSV: Cotonti through 1.0.0 Reflected XSS via message.php lng parameter
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary; CVSS 5.1 (MEDIUM); EPSS percentile 10; sources: NVD, OSV.
- CVE-2026-100521 MEDIUM CVSS 5.1 -
NVD: Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. NVD: Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the browser of any visitor who opens the link, including administrators. OSV: Cotonti through 1.0.0 Reflected XSS via search highlight parameter
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 5.1 (MEDIUM); EPSS percentile 9; sources: NVD, OSV.
- CVE-2026-100523 MEDIUM CVSS 5.1 -
NVD: Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. NVD: Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks. OSV: Cotonti through 1.0.0 Open Redirect via message.php redirect parameter
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 5.1 (MEDIUM); EPSS percentile 8; sources: NVD, OSV.
- CVE-2026-100503 MEDIUM CVSS 4.8 -
NVD: Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. NVD: Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines. OSV: Ghidra through 12.1.4 Heap Use-After-Free in Decompiler
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 4.8 (MEDIUM); EPSS percentile 2; sources: NVD, OSV.
- CVE-2026-100505 MEDIUM CVSS 4.8 -
NVD: Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. NVD: Attackers can craft malicious binaries containing strings or constant byte stores that end in multi-byte lead units to trigger out-of-bounds reads that crash the decompiler or leak adjacent heap memory into decompiled output. OSV: Ghidra 9.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.8 (MEDIUM); EPSS percentile 1; sources: NVD, OSV.
- CVE-2026-100534 LOW CVSS 2.3 -
NVD: OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. NVD: An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority. OSV: OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.3 (LOW); EPSS percentile 17; sources: NVD, OSV.