Description
OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.
Published: 2026-09-26
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation via unauthorized file upload
Action: Apply Patch
AI Analysis

Impact

The flaw allows a sender to place the contents of a local file into an outbound emoji or sticker upload by hijacking the sender‑scoped media policy during those actions. While it does not provide arbitrary file system access or code execution, it grants the sender higher privileges within the Discord integration and can result in data exposure or unauthorized content distribution.

Affected Systems

OpenClaw’s Discord integration npm package (@openclaw/discord) before version 2026.9.3. The issue was addressed in version 2026.9.3.

Risk and Exploitability

The CVSS score of 6 indicates medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. An attacker must already have guild asset action permissions and must know or be able to deduce a usable local file path; the flaw cannot be used for unrestricted filesystem browsing or arbitrary code execution, limiting the potential impact to the authorized scope of the user.

Generated by OpenCVE AI on September 26, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the @openclaw/discord package to version 2026.9.3 or newer.
  • Restrict emoji and sticker upload permissions to trusted roles only so that only authorized users can trigger these actions.
  • Confirm that the media root configuration and policy enforcement remain intact after the upgrade.
  • Implement monitoring for outbound uploads to detect any unexpected file content.

Generated by OpenCVE AI on September 26, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 26 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.
Title Vulnerability in discord
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T02:18:29.070Z

Reserved: 2026-09-26T01:00:40.148Z

Link: CVE-2026-100526

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-26T03:16:57.750

Modified: 2026-09-26T03:16:57.750

Link: CVE-2026-100526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T04:00:05Z

Weaknesses