lowVulnerability

GHSA-cwq8-6f96-g3q4

## Summary Security Scan Failure Does Not Block Plugin Installation (Fail-Open) ## Current Maintainer Triage - Status: open - Normalized severity: low - Assessment: Real in shipped v2026.3.28 plugin install flow, but low severity fits because it still requires an operator to choose installation of an untrusted package and the scan failure was visible rather than silent. ## Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version: `2026.3.31` - Vulnerable version range: `<=2026.3.28` - Patched versions: `>= 2026.3.31` - First stable tag containing the fix: `v2026.3.31` ## Fix Commit(s) - `7a953a52271b9188a5fa830739a4366614ff9916` — 2026-03-30T15:36:08+01:00 - `44b993613601280d46a5b88190e46669fc13d669` — 2026-03-31T23:16:11+09:00 - `0d7f1e2c84eca65df7dee890d9c30e2a841c030a` — 2026-03-31T23:27:20+09:00 - `bf96c67fd1954740aeabfadc7cfe3098bcfc6b68` — 2026-03-31T15:53:29+01:00 OpenClaw thanks @davidluzsilva for reporting.

Properties

ghsa_id
GHSA-cwq8-6f96-g3q4
summary
OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)
severity
low
cve_id
GHSA-cwq8-6f96-g3q4
is_ghsa_only
true
ghsa_published
2026-04-02T21:24:03Z
source_url
https://github.com/advisories/GHSA-cwq8-6f96-g3q4
ghsa_updated
2026-04-02T21:24:04Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Improper Check for Unusual or Exceptional Conditions
[Weakness]Not Failing Securely ('Failing Open')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph