CVE-2026-100526

MEDIUM CVSS 4.0: 6.0 EPSS 0.28%
Updated Sep 28, 2026
OpenClaw
Parameter Value
CVSS 6.0 (MEDIUM)
Affected Versions before 2026.9.3
Type CWE-862 (Missing Authorization)
Vendor OpenClaw
Public PoC No

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution.

The issue is fixed in @openclaw/discord 2026.9.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0