Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5f9p-f3w2-fwch

Опубликовано: 02 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3

Описание

OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains

Summary

In the macOS companion app (currently beta), a parsing mismatch in exec approvals could let shell-chain payloads pass allowlist checks in system.run under specific settings.

Impact

This path requires all of the following:

  • authenticated caller with operator.write
  • paired macOS beta node host
  • exec approvals set to security=allowlist and ask=on-miss

Under those conditions, a shell-chain command could be approved from an incomplete command view and then executed on the paired macOS host.

Default Install Status

Default installs are not affected.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected: <= 2026.2.21-2
  • Patched (planned next release): >= 2026.2.22

Technical Details

The fix hardens macOS allowlist resolution by evaluating shell chains per segment and failing closed on unsafe shell-substitution parsing in allowlist mode.

Product Status Note

The affected macOS companion app path is currently in beta.

Fix Commit(s)

  • 5da03e622119fa012285cdb590fcf4264c965cb5
  • e371da38aab99521c4e076cd3d95fd775e00b784

Release Process Note

patched_versions is pre-set to the planned next npm release (2026.2.22) so once that version is published, this advisory can be published without additional metadata edits.

OpenClaw thanks @tdjackey for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.2.22

2026.2.22

EPSS

Процентиль: 22%
0.00291
Низкий

2.3 Low

CVSS4

Дефекты

CWE-184
CWE-285

Связанные уязвимости

CVSS3: 4.8
nvd
5 месяцев назад

OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired macOS beta node can craft shell-chain payloads that pass incomplete allowlist validation and execute arbitrary commands on the paired host.

CVSS3: 6.4
fstec
6 месяцев назад

Уязвимость ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), связанная с использованием неполного чёрного списка, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 22%
0.00291
Низкий

2.3 Low

CVSS4

Дефекты

CWE-184
CWE-285