GHSA-mhq8-78pj-5j79: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
On POSIX nodes, OpenClaw’s system.run safe-bin checks could approve a command before shell expansion changed how the command was interpreted. A value that appeared to be a safe-bin argument could expand into additional shell words and become a file operand.
This issue is limited to paired POSIX node execution through system.run with safe-bin or allowlist-style auto-approval. It is not an unauthenticated node takeover.
References
Code Behaviors & Features
Detect and mitigate GHSA-mhq8-78pj-5j79 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →