CVE-2026-100564 UNKNOWN

CVE-2026-100564

Published: 2026-09-26

Description

OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute with spreadsheet user permissions when the export is opened in formula-enabled applications.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…