GHSA-q94v-v6m9-jhq9

Suggest an improvement
Source
https://github.com/advisories/GHSA-q94v-v6m9-jhq9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-q94v-v6m9-jhq9/GHSA-q94v-v6m9-jhq9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q94v-v6m9-jhq9
Withdrawn
2026-03-24T19:04:39Z
Published
2026-03-21T03:31:13Z
Modified
2026-03-24T19:16:35Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: OpenClaw has an improper sandbox configuration vulnerability
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-43x4-g22p-3hrq. This link is maintained to preserve external references.

Original Description

OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leverage the disabled OS-level sandbox protections in the Chromium browser container to achieve code execution on the host system.

Database specific
{
    "cwe_ids":  [
        "CWE-1188"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-24T19:04:39Z",
    "nvd_published_at":  "2026-03-21T01:17:07Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

last_known_affected_version_range
"< 2026.2.21"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-q94v-v6m9-jhq9/GHSA-q94v-v6m9-jhq9.json"