Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-392f-ggf5-fp3c

Опубликовано: 02 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

Summary

A paired node could supply Unicode-confusable platform or deviceFamily metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists.

Impact

This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults.

Fix

Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding system.run and system.which unless explicitly allowlisted).

Affected and Patched Versions

  • Affected: <= 2026.2.26
  • Patched: 2026.3.1

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.3.1

2026.3.1

6.9 Medium

CVSS4

Дефекты

CWE-176
CWE-436

6.9 Medium

CVSS4

Дефекты

CWE-176
CWE-436