medium · CVSS v3 5.3 · CVSS v4 6 · EPSS 0.00291
CVE-2026-100533
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Uni…
Description
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary.
Scores
- Severity
- medium
- CVSS v2
- 4.9
- CVSS v3
- 5.3
- CVSS v4
- 6
- EPSS
- 0.00291