mediumVulnerability

GHSA-ff98-w8hj-qrxf

### Summary OpenClaw plugins/extensions run in-process and are treated as trusted code. This advisory tracks trust-boundary clarification around plugin runtime command execution (`runtime.system.runCommandWithTimeout`). ### Impact Plugins already execute with the same OS privileges as the OpenClaw process. Exposing runtime command helpers does not cross an additional sandbox boundary. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published version reviewed: `2026.2.17` - Affected range for this advisory record: `<= 2026.2.17` - Planned patched version metadata: `2026.2.19` (next release line) ### Fix Commit(s) - `2e421f32dfc589c02706265fd3c3137ffc06c4b1` ### Remediation - Install only trusted plugins. - Use `plugins.allow` to pin explicit trusted plugin IDs. - SECURITY.md now explicitly documents that plugin runtime helpers are convenience APIs, not a sandbox boundary. OpenClaw thanks @markmusson for reporting.

Properties

ghsa_id
GHSA-ff98-w8hj-qrxf
severity
medium
summary
OpenClaw plugin runtime command execution is part of trusted plugin boundary
cve_id
GHSA-ff98-w8hj-qrxf
is_ghsa_only
true
ghsa_published
2026-03-03T21:39:26Z
source_url
https://github.com/advisories/GHSA-ff98-w8hj-qrxf
ghsa_updated
2026-03-03T21:39:28Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-ff98-w8hj-qrxf — Ninja Signal Threat Intelligence | Ninja Signal