criticalCVSS 9.7Vulnerability
GHSA-j7p2-qcwm-94v4
## Summary Host exec env override sanitization did not fail closed for several package-manager and related redirect variables that can steer dependency fetches or startup behavior. ## Impact An approved exec request could silently redirect package resolution or runtime bootstrap to attacker-controlled infrastructure and execute trojanized content. ## Affected Component `src/infra/host-env-security-policy.json, src/infra/host-env-security.ts` ## Fixed Versions - Affected: `< 2026.3.22` - Patched: `>= 2026.3.22` ## Fix Fixed by commit `7abfff756d` (`Exec: harden host env override handling across gateway and node`).
Properties
- ghsa_id
- GHSA-j7p2-qcwm-94v4
- severity
- critical
- summary
- OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
- cvss_score
- 9.7
- cve_id
- GHSA-j7p2-qcwm-94v4
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-03-31T23:59:36Z
- source_url
- https://github.com/advisories/GHSA-j7p2-qcwm-94v4
- ghsa_updated
- 2026-03-31T23:59:36Z
Related Entities (3)
AFFECTS (1)
→[Software]npm/OpenClaw
REPORTED_BY (1)
→[Source]GitHub Advisory Database
HAS_WEAKNESS (1)
→[Weakness]Permissive List of Allowed Inputs
Explore deeper with Ninja Signal's threat intelligence graph