mediumCVSS 6.7Vulnerability

GHSA-g87j-gm7p-6vw2

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-h3rm-6x7g-882f. This link is maintained to preserve external references. ## Original Description OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting changes command semantics. Attackers can place malicious local scripts in the working directory to execute unintended code despite operator approval of different command text.

Properties

ghsa_id
GHSA-g87j-gm7p-6vw2
severity
medium
summary
Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
cvss_score
6.7
cve_id
GHSA-g87j-gm7p-6vw2
cvss_vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-03-19T03:30:57Z
source_url
https://github.com/advisories/GHSA-g87j-gm7p-6vw2
ghsa_updated
2026-03-19T16:26:08Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph