Launch Week Day 1: Announcing Security Design Review
LOW 2.6 npm

Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

GHSA-cjq8-m7wj-xmq9

Published ยท Modified

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hjvp-qhm6-wrh2. This link is maintained to preserve external references.

Original Description

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows.

Ready to move

Start Securing

Free, no credit card | First findings in minutes