GHSA-w6f4-3v35-qjhj

Suggest an improvement
Source
https://github.com/advisories/GHSA-w6f4-3v35-qjhj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w6f4-3v35-qjhj/GHSA-w6f4-3v35-qjhj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w6f4-3v35-qjhj
Downstream
Withdrawn
2026-03-24T19:05:12Z
Published
2026-03-21T03:31:13Z
Modified
2026-03-24T19:16:24.269412Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6rcp-vxwf-3mfp. This link is maintained to preserve external references.

Original Description

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation.

Database specific
{
    "nvd_published_at": "2026-03-21T01:17:08Z",
    "severity": "MODERATE",
    "github_reviewed_at": "2026-03-24T19:05:12Z",
    "cwe_ids": [
        "CWE-436",
        "CWE-77"
    ],
    "github_reviewed": true
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2026.2.23

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w6f4-3v35-qjhj/GHSA-w6f4-3v35-qjhj.json"