highCVSS 8.1Vulnerability

GHSA-27pq-2ph8-8x25

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-5cj2-3jr2-5h77. This link is maintained to preserve external references. ## Original Description OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.

Properties

ghsa_id
GHSA-27pq-2ph8-8x25
severity
high
summary
Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
cvss_score
8.1
cve_id
GHSA-27pq-2ph8-8x25
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-06-16T21:31:59Z
source_url
https://github.com/advisories/GHSA-27pq-2ph8-8x25
ghsa_updated
2026-06-18T20:11:49Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/openclaw

AFFECTS (1)

[Software]npm/openclaw

HAS_WEAKNESS (1)

[Weakness]Incomplete List of Disallowed Inputs

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph