CVE-2026-100526: Openclaw Discord

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.

Affected products

  • Openclaw Discord: before 2026.9.3 (fixed in 2026.9.3)

Published 2026-09-26. Last modified 2026-10-08.