highCVSS 8.3Vulnerability

GHSA-3v3j-737j-7g74

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-v2ww-5rh7-2h5v. This link is maintained to preserve external references. ## Original Description OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or command execution.

Properties

ghsa_id
GHSA-3v3j-737j-7g74
severity
high
summary
Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns
cvss_score
8.3
cve_id
GHSA-3v3j-737j-7g74
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
is_ghsa_only
true
ghsa_published
2026-06-16T21:31:59Z
source_url
https://github.com/advisories/GHSA-3v3j-737j-7g74
ghsa_updated
2026-06-18T20:32:43Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/openclaw

AFFECTS (1)

[Software]npm/openclaw

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph