Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vmqr-rc7x-3446

Опубликовано: 03 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints

When sort is explicitly added to tools.exec.safeBins (non-default), the --compress-program option can invoke an external helper and bypass the intended safe-bin approval constraints in allowlist mode.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Vulnerable versions: <=2026.2.21-2
  • Latest published npm version checked during triage: 2026.2.21-2 (as of February 22, 2026)
  • Patched in planned next release: 2026.2.22

Fix Commit(s)

  • 57fbbaebca4d34d17549accf6092ae26eb7b605c

Release Process Note

patched_versions is pre-set to the planned next release (>=2026.2.22). Once that npm release is published, the advisory can be published directly.

OpenClaw thanks @tdjackey for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.2.22

2026.2.22

EPSS

Процентиль: 10%
0.00197
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-15
CWE-78

Связанные уязвимости

CVSS3: 6.7
nvd
5 месяцев назад

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.

CVSS3: 7
fstec
6 месяцев назад

Уязвимость конфигурации tools.exec.safeBins ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 10%
0.00197
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-15
CWE-78