GHSA-x3h8-jrgh-p8jx

Suggest an improvement
Source
https://github.com/advisories/GHSA-x3h8-jrgh-p8jx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-x3h8-jrgh-p8jx/GHSA-x3h8-jrgh-p8jx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x3h8-jrgh-p8jx
Aliases
Downstream
Published
2026-05-04T20:23:35Z
Modified
2026-07-08T08:26:56Z
Summary
OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs
Details

Summary

Exec allowlist analysis rejects shell expansion in unquoted heredocs

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: <= 2026.4.21
  • Fixed version: 2026.4.22

Impact

An allowlisted command containing an unquoted heredoc could hide shell expansion in the heredoc body. That could make the approved command text look safer than what the shell would evaluate at runtime.

Fix

The exec command analyzer now tracks heredoc bodies, rejects unquoted heredoc expansion tokens and continuation-splice bypasses, and preserves quoted heredocs and literal safe text.

Fix Commit(s)

  • b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5

Verification

  • The fix commit is contained in the public v2026.4.22 tag.
  • openclaw@2026.4.22 is published on npm and the compiled package contains the fix.
  • Focused regression coverage for this path passed before publication.

Thanks @VladimirEliTokarev for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-04T20:23:35Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.4.22

Database specific

last_known_affected_version_range
"<= 2026.4.21"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-x3h8-jrgh-p8jx/GHSA-x3h8-jrgh-p8jx.json"