highVulnerability

GHSA-9f72-qcpw-2hxc

### Summary In sandboxed runs, native prompt image auto-load did not honor `tools.fs.workspaceOnly=true`. This optional hardening setting is **not enabled by default**. When operators enabled it, prompt text could still reference mounted out-of-workspace image paths (for example `/agent/secret.png`) and load those image bytes for vision-capable model input. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version at triage time: `2026.2.23` - Vulnerable version range: `<= 2026.2.23` - Patched version (planned next release): `2026.2.24` ### Conditions Required This issue required all of the following: - sandbox mode enabled, - `tools.fs.workspaceOnly=true` configured, - an out-of-workspace mount path reachable from the sandbox (for example `/agent`), - vision-capable model path active for native prompt image loading. ### Technical Details Native prompt image ingestion (`detectAndLoadPromptImages` / `loadImageFromRef`) resolved and read sandbox paths but did not apply the same workspace-root assertion used by file tools when `tools.fs.workspaceOnly` was set. ### Fix Commit(s) - `370d115549c0dadace0902775eea0d5094aedfdc` ### Verification - `pnpm check` - `pnpm exec vitest run --config vitest.gateway.config.ts` - `pnpm test:fast` ### Release Process Note `patched_versions` is pre-set to the planned next release (`2026.2.24`) so once npm release is available, this advisory only needs publish action. OpenClaw thanks @tdjackey for reporting. ### Publication Update (2026-02-25) `[email protected]` is published on npm and contains the fix commit(s) listed above. This advisory now marks `>= 2026.2.24` as patched.

Properties

ghsa_id
GHSA-9f72-qcpw-2hxc
severity
high
summary
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs
cve_id
GHSA-9f72-qcpw-2hxc
is_ghsa_only
true
ghsa_published
2026-03-03T19:08:08Z
source_url
https://github.com/advisories/GHSA-9f72-qcpw-2hxc
ghsa_updated
2026-03-03T19:08:10Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph