---
id: CVE-2026-100533
title: >-
  OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in
  the tools.fs.workspaceOnly feature where Unicode filename fallback can
  normalize validated parent directory components
summary: >-
  OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in
  the tools.fs.workspaceOnly feature where Unicode filename fallback can
  normalize validated parent directory components. Admitted requesters can
  exploit canonical…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.8.1
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:16:58.813'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100533'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-5rx7-34fw-64qg
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-path-traversal-via-unicode-fallback
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.676Z'
---

## Overview

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
