Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5326-6f73-m96w

Опубликовано: 19 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.7
CVSS3: 4.8

Описание

Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5f9p-f3w2-fwch. This link is maintained to preserve external references.

Original Description

OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired macOS beta node can craft shell-chain payloads that pass incomplete allowlist validation and execute arbitrary commands on the paired host.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

Отсутствует

5.7 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-184

5.7 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-184