mediumVulnerability

GHSA-392f-ggf5-fp3c

### Summary A paired node could supply Unicode-confusable `platform` or `deviceFamily` metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists. ### Impact This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults. ### Fix Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding `system.run` and `system.which` unless explicitly allowlisted). ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`

Properties

ghsa_id
GHSA-392f-ggf5-fp3c
severity
medium
summary
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
cve_id
GHSA-392f-ggf5-fp3c
is_ghsa_only
true
ghsa_published
2026-03-02T21:49:33Z
source_url
https://github.com/advisories/GHSA-392f-ggf5-fp3c
ghsa_updated
2026-03-02T21:49:35Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Interpretation Conflict
[Weakness]Improper Handling of Unicode Encoding

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-392f-ggf5-fp3c — Ninja Signal Threat Intelligence | Ninja Signal