GHSA-ff98-w8hj-qrxf

Suggest an improvement
Source
https://github.com/advisories/GHSA-ff98-w8hj-qrxf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-ff98-w8hj-qrxf/GHSA-ff98-w8hj-qrxf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ff98-w8hj-qrxf
Downstream
Published
2026-03-03T21:39:26Z
Modified
2026-03-04T15:14:30.313185Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw plugin runtime command execution is part of trusted plugin boundary
Details

Summary

OpenClaw plugins/extensions run in-process and are treated as trusted code. This advisory tracks trust-boundary clarification around plugin runtime command execution (runtime.system.runCommandWithTimeout).

Impact

Plugins already execute with the same OS privileges as the OpenClaw process. Exposing runtime command helpers does not cross an additional sandbox boundary.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published version reviewed: 2026.2.17
  • Affected range for this advisory record: <= 2026.2.17
  • Planned patched version metadata: 2026.2.19 (next release line)

Fix Commit(s)

  • 2e421f32dfc589c02706265fd3c3137ffc06c4b1

Remediation

  • Install only trusted plugins.
  • Use plugins.allow to pin explicit trusted plugin IDs.
  • SECURITY.md now explicitly documents that plugin runtime helpers are convenience APIs, not a sandbox boundary.

OpenClaw thanks @markmusson for reporting.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-03T21:39:26Z",
    "cwe_ids": [
        "CWE-78"
    ],
    "severity": "MODERATE",
    "nvd_published_at": null
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2026.2.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-ff98-w8hj-qrxf/GHSA-ff98-w8hj-qrxf.json"