Description
OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating sender's policy had removed. When session-memory filename generation was enabled for an agent reachable by lower-trust senders, model-mediated instructions could cause the helper to invoke tools outside that sender's effective policy; the demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes. The issue is fixed in 2026.8.1; as a workaround, disable session-memory filename generation for agents reachable by lower-trust senders.
Published: 2026-09-26
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

OpenClaw before 2026.8.1 does not correctly enforce sender tool policies when generating session‑memory filenames. The filename generator can create an embedded helper that retains tools removed by the originating sender's policy. When a model processes a model‑mediated instruction, the helper can invoke tools outside the sender's effective policy, leading to the creation of persistent scheduled work. This flaw allows actors using lower‑trust senders to bypass tool restrictions and run unintended commands, compromising the integrity of the system's operation.

Affected Systems

The vulnerability affects the npm package openclaw in all releases prior to 2026.8.1. No specific sub‑version list is provided beyond the run‑before‑2026.8.1 range, so any installation of openclaw older than 2026.8.1 is considered vulnerable.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting exposure risk may vary. The likely attack vector is injection of instructions via a model that has access to lower‑trust senders; exploitation requires the model to act on the injected instruction and the helper to expose the forbidden tools. The issue is resolved in 2026.8.1. Until the update can be applied, disabling session‑memory filename generation for agents reachable by lower‑trust senders is an available workaround.

Generated by OpenCVE AI on September 26, 2026 at 03:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.8.1 or later
  • Disable session‑memory filename generation for agents reachable by lower‑trust senders
  • Verify that sender policies are properly enforced and review agent configurations to limit helper tool exposure

Generated by OpenCVE AI on September 26, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 26 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating sender's policy had removed. When session-memory filename generation was enabled for an agent reachable by lower-trust senders, model-mediated instructions could cause the helper to invoke tools outside that sender's effective policy; the demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes. The issue is fixed in 2026.8.1; as a workaround, disable session-memory filename generation for agents reachable by lower-trust senders.
Title OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T02:18:41.920Z

Reserved: 2026-09-26T01:02:06.786Z

Link: CVE-2026-100545

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-26T03:17:00.590

Modified: 2026-09-26T03:17:00.590

Link: CVE-2026-100545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T03:45:04Z

Weaknesses