GHSA-jf25-7968-h2h5

Suggest an improvement
Source
https://github.com/advisories/GHSA-jf25-7968-h2h5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jf25-7968-h2h5/GHSA-jf25-7968-h2h5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jf25-7968-h2h5
Aliases
Downstream
Published
2026-04-17T21:58:24Z
Modified
2026-05-05T16:11:49Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: screen_record outPath bypassed workspace-only filesystem guard
Details

Summary

screen_record outPath bypassed workspace-only filesystem guard.

Affected Packages / Versions

  • Package: openclaw
  • Ecosystem: npm
  • Affected versions: < 2026.4.10
  • Patched versions: >= 2026.4.10

Impact

The node-host screen recording tool could honor an outPath outside the workspace guard, allowing an authorized tool call to write outside the intended workspace boundary.

Technical Details

The fix applies the workspace-root guard to node tool outPath handling, including screen recording paths.

Fix

The issue was fixed in #63551. The first stable tag containing the fix is v2026.4.10, and openclaw@2026.4.14 includes the fix.

Fix Commit(s)

  • 635bb35b68d8faa5bfa2fda35feadd315122748a
  • PR: #63551

Release Process Note

Users should upgrade to openclaw 2026.4.10 or newer. The latest npm release, 2026.4.14, already includes the fix.

Credits

Thanks to @anshumanbh for reporting this issue.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-17T21:58:24Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.4.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jf25-7968-h2h5/GHSA-jf25-7968-h2h5.json"