#VU125125 Improper handling of highly compressed data in OpenClaw - CVE-2026-32044
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the tar.bz2 installer path in src/agents/skills-install-download.ts when processing untrusted .tar.bz2 skill archives. A remote attacker can trick the victim into opening a crafted archive to cause a denial of service.
User interaction is required to process the crafted archive during skill install.