Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full. If an operator approves installation of such a malicious or compromised skill archive, over-limit files or entry counts are persisted in the skill tools directory, consuming disk space or inodes. The issue bypasses OpenClaw's extraction budgets but does not by itself execute archive contents. Fixed in 2026.8.1. | |
| Title | OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2 | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T02:18:39.901Z
Reserved: 2026-09-26T01:01:36.095Z
Link: CVE-2026-100542
No data.
Status : Received
Published: 2026-09-26T03:17:00.140
Modified: 2026-09-26T03:17:00.140
Link: CVE-2026-100542
No data.
OpenCVE Enrichment
Updated: 2026-09-26T06:30:03Z