---
id: CVE-2026-100536
title: >-
  OpenClaw versions before 2026.8.1 fail to validate all source fields in
  structured message attachments, allowing attackers to hide unvalidated host
  paths behind allowed attachment sources
summary: >-
  OpenClaw versions before 2026.8.1 fail to validate all source fields in
  structured message attachments, allowing attackers to hide unvalidated host
  paths behind allowed attachment sources. Attackers can exploit this by
  providing multiple…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.8.1
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:16:59.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100536'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-fphf-69cp-h5xw
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-path-traversal-via-structured-attachments
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.677Z'
epss: 0.00429
epssPercentile: 0.34609
---

## Overview

OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to read and send known host files that would otherwise be rejected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
