mediumVulnerability
GHSA-f8r2-vg7x-gh8m
### Summary `matchesExecAllowlistPattern` normalized patterns and targets with lowercasing and compiled glob matching too broadly on POSIX. In addition, the `?` wildcard could match `/`, which allowed matches to cross path segments. ### Impact These matching rules could overmatch allowlist entries and permit commands or executable paths that an operator did not intend to approve. ### Affected versions `openclaw` `<= 2026.3.8` ### Patch Fixed in `openclaw` `2026.3.11` and included in later releases such as `2026.3.12`. Exec allowlist matching now respects the intended path semantics, and regression tests cover the POSIX case-folding and slash-crossing cases.
Properties
- ghsa_id
- GHSA-f8r2-vg7x-gh8m
- severity
- medium
- summary
- OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
- cve_id
- GHSA-f8r2-vg7x-gh8m
- is_ghsa_only
- true
- ghsa_published
- 2026-03-13T20:55:03Z
- source_url
- https://github.com/advisories/GHSA-f8r2-vg7x-gh8m
- ghsa_updated
- 2026-03-13T20:55:05Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (2)
→[Weakness]Improper Handling of Case Sensitivity
→[Weakness]Permissive Regular Expression
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph