OpenShell mirror mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup
openclaw (npm)2026.3.31<=2026.3.24>= 2026.3.28v2026.3.28c02ee8a3a4cb390b23afdf21317aa8b2096854d1 — 2026-03-25T19:59:07Z2026.3.28.Thanks @tdjackey for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-07T18:11:21Z",
"cwe_ids": [
"CWE-829"
],
"severity": "MODERATE",
"nvd_published_at": null
}