Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223844 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-100597PATCHED
openclaw · openclaw

OpenClaw before 2026.7.1 Path Traversal via Filesystem Race

Description

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed operation to delete, create, or rename a host path outside the intended mirror root with the permissions of the OpenClaw process user. This does not require an operator to have granted host filesystem access outside the sandbox. The issue is fixed in 2026.7.1.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-crg9-c62w-j2p5(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-path-traversal-via-filesystem-race(third-party-advisory)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-100597 | OpenClaw up to 2026.6.9 OpenShell race condition
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.7.1
CWECWE-367
PublishedSep 26, 2026
Last enriched1d ago
Trending Score22
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-100604EXP
ClawHub Authentication Bypass via Former Publisher Skill Control
Trending: 47
HIGHCVE-2026-100599EXP
OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
Trending: 36
HIGHCVE-2026-100588
OpenClaw before 2026.7.1 Authentication Bypass via node.invoke
Trending: 22
HIGHCVE-2026-100580
OpenClaw before 2026.7.1 Remote Code Execution via cron tool
Trending: 22
HIGHCVE-2026-100579
OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester
Trending: 22

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 26, 2026
Patch Available
Sep 26, 2026
Discovered by ZDM
Sep 26, 2026