Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4g5x-2jfc-xm98

Опубликовано: 07 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 6.5

Описание

OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk

Summary

Tlon media downloads can bypass core safety limits and exhaust disk

Current Maintainer Triage

  • Status: narrow
  • Normalized severity: low
  • Assessment: Shipped v2026.3.28 Tlon media downloads bypassed core size/count/cleanup limits, but this is availability-only resource exhaustion in a bundled plugin path, so low.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.3.31
  • Vulnerable version range: <=2026.3.28
  • Patched versions: >= 2026.3.31
  • First stable tag containing the fix: v2026.3.31

Fix Commit(s)

  • 2194587d70d2aef863508b945319c5a7c88b12ce — 2026-03-31T19:40:15+09:00

Release Process Note

  • The fix is already present in released version 2026.3.31.
  • This draft looks ready for final maintainer disposition or publication, not additional code-fix work.

Thanks @AntAISecurityLab for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

<= 2026.3.28

2026.3.31

EPSS

Процентиль: 26%
0.00343
Низкий

6.3 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-434
CWE-770

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk space by downloading media files without triggering intended safety restrictions, causing availability impact.

EPSS

Процентиль: 26%
0.00343
Низкий

6.3 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-434
CWE-770