HIGH 8.3 npm

Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

GHSA-gwcq-453v-2frr

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-mhq8-78pj-5j79. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration data.

Ready to move

Start Securing

Free, no credit card | First findings in minutes