Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100602— ClawHub Changelog Preview Information Disclosure via Authorization Bypass

Quick assessment

Affected
openclaw clawhub
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ClawHub(openclaw/clawhub 应用程序/后端)在“变更日志预览”功能中存在缺失的授权检查漏洞。已登录用户可以通过调用 操作,访问其无权访问的技能(skill);在获取前一个版本时,未强制执行正常内容访问所需的文件读取权限验证,导致最多 8,000 个字符的隔离内容(quarantined content)被提交给 AI 提供商,并反映在返回给调用者的预览结果中,从而泄露受限的技能内容。 该问题已在修订版本 中得到确认,但尚未完全确定受影响的历史版本范围。该漏洞已通过 PR #3682 修复,该修

CVSS 6.5 · Medium EPSS 0.29% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100602

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ClawHub Changelog Preview Information Disclosure via Authorization Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization enforced on normal content access, and up to 8,000 characters of quarantined content may be submitted to the AI provider and reflected in the preview returned to the caller, disclosing restricted skill content. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3682, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openclaw clawhub 0 ~ 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 -

II. Public POCs for CVE-2026-100602

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100602

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100602 (1)

Other References for CVE-2026-100602 (2)

Same Patch Batch · openclaw · 2026-09-26 · 79 CVEs total

CVE-2026-100580 8.8 HIGH OpenClaw before 2026.7.1 Remote Code Execution via cron tool
CVE-2026-100575 8.8 HIGH OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM
CVE-2026-100599 8.8 HIGH OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
CVE-2026-100544 8.8 HIGH openclaw voice-call before 2026.8.1 Authorization Bypass
CVE-2026-100596 8.8 HIGH OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
CVE-2026-100586 8.8 HIGH OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind
CVE-2026-100587 8.8 HIGH OpenClaw before 2026.7.1 Authorization Bypass via Codex Install
CVE-2026-100552 8.8 HIGH OpenClaw before 2026.8.1 Policy Bypass via Native Tools
CVE-2026-100551 8.3 HIGH OpenClaw iOS Control UI TLS Pin Enforcement Bypass
CVE-2026-100588 8.3 HIGH OpenClaw before 2026.7.1 Authentication Bypass via node.invoke
CVE-2026-100589 8.3 HIGH OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
CVE-2026-100568 8.3 HIGH OpenClaw before 2026.8.1 Unauthorized Command Job Access
CVE-2026-100557 8.3 HIGH OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch
CVE-2026-100567 8.2 HIGH OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname
CVE-2026-100532 8.1 HIGH openclaw WhatsApp before 2026.8.1 Authentication Bypass
CVE-2026-100585 8.0 HIGH OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel
CVE-2026-100561 8.0 HIGH OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper
CVE-2026-100559 8.0 HIGH OpenClaw before 2026.8.1 Command Injection via Escaped Newlines
CVE-2026-100570 7.8 HIGH OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS
CVE-2026-100597 7.8 HIGH OpenClaw before 2026.7.1 Path Traversal via Filesystem Race

Showing top 20 of 79 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-100602

No comments yet


Leave a comment