GHSA-392f-ggf5-fp3c

Suggest an improvement
Source
https://github.com/advisories/GHSA-392f-ggf5-fp3c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-392f-ggf5-fp3c/GHSA-392f-ggf5-fp3c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-392f-ggf5-fp3c
Downstream
Published
2026-03-02T21:49:33Z
Modified
2026-03-04T15:10:26Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
Details

Summary

A paired node could supply Unicode-confusable platform or deviceFamily metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists.

Impact

This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults.

Fix

Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding system.run and system.which unless explicitly allowlisted).

Affected and Patched Versions

  • Affected: <= 2026.2.26
  • Patched: 2026.3.1
Database specific
{
    "cwe_ids": [
        "CWE-176",
        "CWE-436"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-02T21:49:33Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-392f-ggf5-fp3c/GHSA-392f-ggf5-fp3c.json"