highVulnerability

GHSA-7ff8-xjh3-mgh6

### Summary In `openclaw` versions up to and including `2026.2.22-2`, a non-default exec-approval configuration could allow a skill-name collision to bypass an `ask=on-miss` prompt. When `autoAllowSkills=true`, a path-scoped executable such as `./skill-bin` could resolve to basename `skill-bin`, satisfy the `skills` allowlist segment, and run without prompting for approval. ### Affected Packages / Versions - Package: `npm openclaw` - Affected versions: `<= 2026.2.22-2` - Patched versions: `>= 2026.2.23` (released) ### Configuration Scope (Not Default) This behavior requires non-default settings and does not affect default installs. Required conditions: - `autoAllowSkills=true` (default is `false`) - `system.run` with `security=allowlist` - `ask=on-miss` ### Technical Details The allowlist evaluator accepted `skills` satisfaction by bin-name match, so `./skill-bin` could match `skillBins.has("skill-bin")` after resolution. The fix hardens skill auto-allow matching by requiring: - a pathless invocation token (no `/` or `\\`), and - a trusted resolved executable path for that skill bin on the machine where skills run. This preserves normal `skill-bin ...` behavior while preventing `./<skill-bin>` and absolute-path basename collisions from auto-satisfying `skills`. ### Impact In affected non-default configurations, approval prompts could be skipped for commands that should have required operator confirmation. ### Fix Commit(s) - `ffd63b7a2c4c6d5aeb4710ef951d5794ad7ad77b` (`fix(security): trust resolved skill-bin paths in allowlist auto-allow`) OpenClaw thanks @tdjackey for reporting.

Properties

ghsa_id
GHSA-7ff8-xjh3-mgh6
severity
high
summary
OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec prompt
cve_id
GHSA-7ff8-xjh3-mgh6
is_ghsa_only
true
ghsa_published
2026-03-03T22:13:53Z
source_url
https://github.com/advisories/GHSA-7ff8-xjh3-mgh6
ghsa_updated
2026-03-03T22:13:54Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Incorrect Authorization
[Weakness]Incorrect Privilege Assignment

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph