Опубликовано: 19 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 7.1
Описание
Duplicate Advisory: Exec allowlist wrapper analysis did not unwrap env/shell dispatch chains
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-jj82-76v6-933r. This link is maintained to preserve external references.
Original Description
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatch wrapper chains. Attackers can route execution through wrapper binaries like env bash to smuggle payloads that satisfy allowlist entries while executing non-allowlisted commands.
Ссылки
- https://github.com/openclaw/openclaw/security/advisories/GHSA-jj82-76v6-933r
- https://nvd.nist.gov/vuln/detail/CVE-2026-27566
- https://github.com/openclaw/openclaw/commit/2b63592be57782c8946e521bc81286933f0f99c7
- https://www.vulncheck.com/advisories/openclaw-allowlist-bypass-via-wrapper-binary-unwrapping-in-system-run
Пакеты
Наименование
openclaw
npm
Затронутые версииВерсия исправления
Отсутствует
7.1 High
CVSS4
7.1 High
CVSS3
Дефекты
CWE-78
7.1 High
CVSS4
7.1 High
CVSS3
Дефекты
CWE-78