NVD HIGH: CVE-2026-100535 — OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose t...
OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to
CVE-2026-100535