CVE-2026-100536

CVE-2026-100536 published: OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to by...

View full NVD advisory → ← Back to CVE watch