Junglewise Threat Intelligence

CVE-2026-100602: ClawHub missing authorization check in changelog preview

CVE-2026-100602 · Severity: medium · CVSS 6.5 · Published 2026-09-26

Technologies: Openclaw ClawHub. Vendors: Openclaw.

Executive brief

ClawHub is a skill marketplace and AI tool development platform. An authenticated user can generate a changelog preview for skills they do not have permission to access, causing restricted content to be sent to an external AI provider and potentially leaked in the preview. This bypasses normal content authorization checks.

Technical details

Missing authorization check in the skills:generateChangelogPreview action allows authenticated attackers to bypass file-read authorization. The vulnerability permits reading up to 8,000 characters of quarantined (restricted) previous-version content and submitting it to an external AI provider. The attack requires authentication but no other preconditions; the fix adds authorization validation before processing preview requests.

Affected products

  • OpenClaw ClawHub before revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650

Timeline

  • 2026-09-11: disclosed: Fixed and deployed to clawhub.ai
  • 2026-09-26: advisory: Security advisory published
  • 2026-09-11: patched: PR #3682 included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650

References

Related threats