CVE-2026-100542
Last modified
CVE-2026-100542 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full.
Description
OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full. If an operator approves installation of such a malicious or compromised skill archive, over-limit files or entry counts are persisted in the skill tools directory, consuming disk space or inodes. The issue bypasses OpenClaw's extraction budgets but does not by itself execute archive contents. Fixed in 2026.8.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenClaw | OpenClaw | >= 2026.5.28, < 2026.8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100542?
How severe is CVE-2026-100542?
How do I fix CVE-2026-100542?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100537OpenClaw (npm package 'openclaw') before 2026.8.1 fails to a…3.1
- CVE-2026-100538OpenClaw (npm package 'openclaw') before 2026.8.1 does not a…6.5
- CVE-2026-100539OpenClaw (npm package 'openclaw') before 2026.8.1 fails to r…2.6
- CVE-2026-10054In affected versions of Eclipse Theia (1.8.1 and later), the…8.8
- CVE-2026-100540OpenClaw Feishu before 2026.8.1 fails to validate whether a …6.8
- CVE-2026-100541OpenClaw's Matrix integration (npm package @openclaw/matrix)…7.5
- CVE-2026-100543OpenClaw (npm package openclaw) before 2026.8.1 could includ…7.5
- CVE-2026-100544openclaw's @openclaw/voice-call package before 2026.8.1 laun…8.8
- CVE-2026-100545OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectl…5.3
- CVE-2026-100546OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and <…6.4
- CVE-2026-100547OpenClaw is a coding agent distributed as the npm package `o…5.5
- CVE-2026-100548OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and …5.3
Are you affected by CVE-2026-100542?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
