Описание
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
Summary
A paired node could supply Unicode-confusable platform or deviceFamily metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists.
Impact
This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults.
Fix
Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding system.run and system.which unless explicitly allowlisted).
Affected and Patched Versions
- Affected:
<= 2026.2.26 - Patched:
2026.3.1
Пакеты
Наименование
openclaw
npm
Затронутые версииВерсия исправления
< 2026.3.1
2026.3.1
6.9 Medium
CVSS4
Дефекты
CWE-176
CWE-436
6.9 Medium
CVSS4
Дефекты
CWE-176
CWE-436