Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27pq-2ph8-8x25

Опубликовано: 16 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.6
CVSS3: 8.1

Описание

Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5cj2-3jr2-5h77. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

Отсутствует

7.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-184

7.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-184