GHSA-7ff8-xjh3-mgh6
### Summary In `openclaw` versions up to and including `2026.2.22-2`, a non-default exec-approval configuration could allow a skill-name collision to bypass an `ask=on-miss` prompt. When `autoAllowSkills=true`, a path-scoped executable such as `./skill-bin` could resolve to basename `skill-bin`, satisfy the `skills` allowlist segment, and run without prompting for approval. ### Affected Packages / Versions - Package: `npm openclaw` - Affected versions: `<= 2026.2.22-2` - Patched versions: `>= 2026.2.23` (released) ### Configuration Scope (Not Default) This behavior requires non-default settings and does not affect default installs. Required conditions: - `autoAllowSkills=true` (default is `false`) - `system.run` with `security=allowlist` - `ask=on-miss` ### Technical Details The allowlist evaluator accepted `skills` satisfaction by bin-name match, so `./skill-bin` could match `skillBins.has("skill-bin")` after resolution. The fix hardens skill auto-allow matching by requiring: - a pathless invocation token (no `/` or `\\`), and - a trusted resolved executable path for that skill bin on the machine where skills run. This preserves normal `skill-bin ...` behavior while preventing `./<skill-bin>` and absolute-path basename collisions from auto-satisfying `skills`. ### Impact In affected non-default configurations, approval prompts could be skipped for commands that should have required operator confirmation. ### Fix Commit(s) - `ffd63b7a2c4c6d5aeb4710ef951d5794ad7ad77b` (`fix(security): trust resolved skill-bin paths in allowlist auto-allow`) OpenClaw thanks @tdjackey for reporting.
Properties
- ghsa_id
- GHSA-7ff8-xjh3-mgh6
- severity
- high
- summary
- OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec prompt
- cve_id
- GHSA-7ff8-xjh3-mgh6
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T22:13:53Z
- source_url
- https://github.com/advisories/GHSA-7ff8-xjh3-mgh6
- ghsa_updated
- 2026-03-03T22:13:54Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph