---
id: CVE-2026-100549
title: >-
  OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in
  QQBot voice attachment handling where filenames are decoded twice, allowing
  encoded traversal segments to reappear after sanitization
summary: >-
  OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in
  QQBot voice attachment handling where filenames are decoded twice, allowing
  encoded traversal segments to reappear after sanitization. Attackers can
  supply craft…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-22
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.8.1
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:17:01.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100549'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-rm45-4jx5-2927
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-path-traversal-via-qqbot-voice-filenames
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.681Z'
epss: 0.00276
epssPercentile: 0.17954
---

## Overview

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
