Описание
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can execute unintended local package-manager executables during dependency setup to compromise the build environment.
Уязвимые конфигурации
Конфигурация 1Версия до 2026.4.29 (исключая)
Одно из
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
cpe:2.3:a:openclaw:openclaw:2026.4.29:beta1:*:*:*:node.js:*:*
cpe:2.3:a:openclaw:openclaw:2026.4.29:beta2:*:*:*:node.js:*:*
cpe:2.3:a:openclaw:openclaw:2026.4.29:beta3:*:*:*:node.js:*:*
cpe:2.3:a:openclaw:openclaw:2026.4.29:beta4:*:*:*:node.js:*:*
EPSS
Процентиль: 2%
0.00118
Низкий
7.1 High
CVSS3
Дефекты
CWE-426
Связанные уязвимости
CVSS3: 7.1
github
около 1 месяца назад
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
EPSS
Процентиль: 2%
0.00118
Низкий
7.1 High
CVSS3
Дефекты
CWE-426