CVE-2026-100533
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 26, 2026
Vendor
unknown
Description
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary.