GHSA-ff98-w8hj-qrxf
### Summary OpenClaw plugins/extensions run in-process and are treated as trusted code. This advisory tracks trust-boundary clarification around plugin runtime command execution (`runtime.system.runCommandWithTimeout`). ### Impact Plugins already execute with the same OS privileges as the OpenClaw process. Exposing runtime command helpers does not cross an additional sandbox boundary. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published version reviewed: `2026.2.17` - Affected range for this advisory record: `<= 2026.2.17` - Planned patched version metadata: `2026.2.19` (next release line) ### Fix Commit(s) - `2e421f32dfc589c02706265fd3c3137ffc06c4b1` ### Remediation - Install only trusted plugins. - Use `plugins.allow` to pin explicit trusted plugin IDs. - SECURITY.md now explicitly documents that plugin runtime helpers are convenience APIs, not a sandbox boundary. OpenClaw thanks @markmusson for reporting.
Properties
- ghsa_id
- GHSA-ff98-w8hj-qrxf
- severity
- medium
- summary
- OpenClaw plugin runtime command execution is part of trusted plugin boundary
- cve_id
- GHSA-ff98-w8hj-qrxf
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T21:39:26Z
- source_url
- https://github.com/advisories/GHSA-ff98-w8hj-qrxf
- ghsa_updated
- 2026-03-03T21:39:28Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph