criticalCVSS 9.7Vulnerability

GHSA-j7p2-qcwm-94v4

## Summary Host exec env override sanitization did not fail closed for several package-manager and related redirect variables that can steer dependency fetches or startup behavior. ## Impact An approved exec request could silently redirect package resolution or runtime bootstrap to attacker-controlled infrastructure and execute trojanized content. ## Affected Component `src/infra/host-env-security-policy.json, src/infra/host-env-security.ts` ## Fixed Versions - Affected: `< 2026.3.22` - Patched: `>= 2026.3.22` ## Fix Fixed by commit `7abfff756d` (`Exec: harden host env override handling across gateway and node`).

Properties

ghsa_id
GHSA-j7p2-qcwm-94v4
severity
critical
summary
OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
cvss_score
9.7
cve_id
GHSA-j7p2-qcwm-94v4
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-03-31T23:59:36Z
source_url
https://github.com/advisories/GHSA-j7p2-qcwm-94v4
ghsa_updated
2026-03-31T23:59:36Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Permissive List of Allowed Inputs

Explore deeper with Ninja Signal's threat intelligence graph