CVE-2026-100538

CVE-2026-100538 published: OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a known loc...

View full NVD advisory → ← Back to CVE watch