CVE-2026-100542 Overview
CVE-2026-100542 is a resource consumption vulnerability [CWE-400] in the OpenClaw npm package (openclaw). Affected versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer. The installer treats bounded command-output suffixes as complete archive listings. A crafted .tar.bz2 or .tbz2 skill archive can push prohibited entries out of both retained listings, allowing entry-count and size checks to pass. The archive is then extracted in full, writing over-limit files or inode counts to the skill tools directory. The flaw bypasses extraction budgets but does not itself execute archive contents.
Critical Impact
An operator who approves a malicious skill archive can exhaust disk space or inodes on the host system, bypassing OpenClaw's extraction limits.
Affected Products
- OpenClaw npm package (openclaw) >= 2026.5.28
- OpenClaw npm package (openclaw) < 2026.8.1
- Systems running the OpenClaw tar.bz2 skill installer
Discovery Timeline
- 2026-09-26 - CVE-2026-100542 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100542
Vulnerability Analysis
The OpenClaw skill installer validates .tar.bz2 and .tbz2 archives before extraction. It inspects archive listings produced by external commands to enforce entry-count and total-size budgets. The installer retains only bounded suffixes of this command output and treats those suffixes as complete listings. An attacker who controls the archive can arrange entries so that over-budget items are pushed out of both retained listings. The pre-extraction checks then evaluate a truncated view and incorrectly report that the archive is within limits.
Once the checks pass, the installer extracts the archive in full. The persisted files on disk exceed the enforced budgets, consuming space or inodes in the skill tools directory. Operator approval is required before installation proceeds, which raises the exploitation bar. However, a compromised upstream skill or a trusted-looking archive can still deliver the payload.
Root Cause
The root cause is improper validation of archive metadata [CWE-400]. The installer treats a bounded buffer of command output as authoritative, rather than parsing the full listing. This mismatch between the validated view and the extracted content lets a crafted archive bypass size and entry-count constraints.
Attack Vector
Exploitation requires an operator to approve installation of a crafted or compromised skill archive. The attacker supplies a .tar.bz2 or .tbz2 file whose entry ordering hides over-limit items from the installer's truncated listing. After approval, extraction writes the full payload to disk and consumes resources beyond the intended budget. The vulnerability does not grant code execution on its own.
See the GitHub Security Advisory GHSA-6xpv-wwr5-265h and the VulnCheck Advisory on OpenClaw for additional technical detail.
Detection Methods for CVE-2026-100542
Indicators of Compromise
- Unexpected growth of the OpenClaw skill tools directory following a recent skill installation.
- Installed skill archives containing significantly more files or bytes than reported by the installer logs.
- Disk space or inode exhaustion alerts on hosts that run the openclaw npm package.
Detection Strategies
- Inventory installed OpenClaw versions and flag any instance between 2026.5.28 and 2026.8.0 inclusive.
- Compare the reported entry count and size of each installed skill against the actual on-disk footprint under the skill tools directory.
- Review installation audit logs for .tar.bz2 or .tbz2 skill approvals and correlate with filesystem telemetry.
Monitoring Recommendations
- Monitor filesystem usage on hosts running OpenClaw and alert on abnormal increases in file counts or sizes under the skill tools directory.
- Track skill installation events and record archive source, hash, and approving operator.
- Enable inode-level monitoring on partitions that host OpenClaw skill data to detect inode exhaustion attempts early.
How to Mitigate CVE-2026-100542
Immediate Actions Required
- Upgrade the openclaw npm package to version 2026.8.1 or later on all affected hosts.
- Audit recently installed skills and remove any archive whose on-disk size or entry count does not match installer-reported values.
- Restrict operator approval of skill archives to vetted, signed sources until upgrades are complete.
Patch Information
The issue is fixed in OpenClaw 2026.8.1. Upgrade using npm install openclaw@2026.8.1 or pin to a later release. Refer to the GitHub Security Advisory GHSA-6xpv-wwr5-265h for release notes.
Workarounds
- Disable installation of .tar.bz2 and .tbz2 skill archives until the package is upgraded.
- Enforce filesystem quotas on the skill tools directory to cap the impact of over-budget extraction.
- Validate archive contents out-of-band by re-listing with a trusted tar implementation and comparing against installer output before approving installation.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.