mediumVulnerability
GHSA-392f-ggf5-fp3c
### Summary A paired node could supply Unicode-confusable `platform` or `deviceFamily` metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists. ### Impact This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults. ### Fix Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding `system.run` and `system.which` unless explicitly allowlisted). ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`
Properties
- ghsa_id
- GHSA-392f-ggf5-fp3c
- severity
- medium
- summary
- OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
- cve_id
- GHSA-392f-ggf5-fp3c
- is_ghsa_only
- true
- ghsa_published
- 2026-03-02T21:49:33Z
- source_url
- https://github.com/advisories/GHSA-392f-ggf5-fp3c
- ghsa_updated
- 2026-03-02T21:49:35Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (2)
→[Weakness]Interpretation Conflict
→[Weakness]Improper Handling of Unicode Encoding
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph