mediumVulnerability

GHSA-f8r2-vg7x-gh8m

### Summary `matchesExecAllowlistPattern` normalized patterns and targets with lowercasing and compiled glob matching too broadly on POSIX. In addition, the `?` wildcard could match `/`, which allowed matches to cross path segments. ### Impact These matching rules could overmatch allowlist entries and permit commands or executable paths that an operator did not intend to approve. ### Affected versions `openclaw` `<= 2026.3.8` ### Patch Fixed in `openclaw` `2026.3.11` and included in later releases such as `2026.3.12`. Exec allowlist matching now respects the intended path semantics, and regression tests cover the POSIX case-folding and slash-crossing cases.

Properties

ghsa_id
GHSA-f8r2-vg7x-gh8m
severity
medium
summary
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
cve_id
GHSA-f8r2-vg7x-gh8m
is_ghsa_only
true
ghsa_published
2026-03-13T20:55:03Z
source_url
https://github.com/advisories/GHSA-f8r2-vg7x-gh8m
ghsa_updated
2026-03-13T20:55:05Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Improper Handling of Case Sensitivity
[Weakness]Permissive Regular Expression

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-f8r2-vg7x-gh8m — Ninja Signal Threat Intelligence | Ninja Signal