GHSA-fm77-94qm-4894

Suggest an improvement
Source
https://github.com/advisories/GHSA-fm77-94qm-4894
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fm77-94qm-4894/GHSA-fm77-94qm-4894.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fm77-94qm-4894
Aliases
Published
2026-05-14T21:30:47Z
Modified
2026-07-21T14:45:29Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Crabbox: environment variable exposure vulnerability
Details

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive environment variable allowlisting in repo-local Crabbox configuration to serialize sensitive environment variables into remote command execution, exposing credentials to the remote environment.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-21T19:29:23Z",
    "nvd_published_at": "2026-05-14T20:17:21Z",
    "severity": "CRITICAL"
}
References

Affected packages

Go / github.com/openclaw/crabbox

Package

Name
github.com/openclaw/crabbox
View open source insights on deps.dev
Purl
pkg:golang/github.com/openclaw/crabbox

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fm77-94qm-4894/GHSA-fm77-94qm-4894.json"