CSV Formula Injection Vulnerability in OpenClaw by OpenClaw Team
CVE-2026-100563
What is CVE-2026-100563?
OpenClaw versions prior to 2026.8.1 are susceptible to a CSV formula injection vulnerability. This stems from the application failing to properly neutralize leading characters in session labels when exporting data to CSV format. If a malicious lower-trust participant can influence the session label or user message, they can include a cell that spreadsheet applications may interpret as a formula. If this exported file is then opened in a spreadsheet with formula evaluation enabled, the malicious input could execute with the permissions of the user opening the file. While OpenClaw does not directly execute any formulas, the implications can be severe depending on the spreadsheet's security settings. Users are advised to upgrade to version 2026.8.1 or later to mitigate this risk.
Affected Version(s)
OpenClaw 0 < 2026.8.1
OpenClaw 2026.8.1
