mediumCVSS 5.5Vulnerability

GHSA-77hf-7fqf-f227

### Summary The `tar.bz2` installer path in `src/agents/skills-install-download.ts` used shell tar preflight/extract logic that did not share the same hardening guarantees as the centralized archive extractor. This allowed crafted `.tar.bz2` archives to bypass special-entry blocking and extracted-size guardrails enforced on other archive paths, causing local availability impact during skill install. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published at triage time: `2026.3.1` - Affected range: `<= 2026.3.1` - Patched in: `2026.3.2` (released) ### Impact Local DoS / availability impact when processing untrusted `.tar.bz2` skill archives. ### Fix Commit(s) - `0dbb92dd2bcf9a32379d11c0f11ed016669dae3e` ### Related advisories - Canonical overlap (closed): GHSA-3pj7-x8jr-jvj8 - Duplicate variant (closed): GHSA-rgr7-g85h-6v82

Properties

ghsa_id
GHSA-77hf-7fqf-f227
severity
medium
summary
OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)
cvss_score
5.5
cve_id
GHSA-77hf-7fqf-f227
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-03-03T21:32:35Z
source_url
https://github.com/advisories/GHSA-77hf-7fqf-f227
ghsa_updated
2026-03-03T21:32:38Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph