mediumCVSS 5.3Vulnerability

GHSA-q94v-v6m9-jhq9

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-43x4-g22p-3hrq. This link is maintained to preserve external references. ## Original Description OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leverage the disabled OS-level sandbox protections in the Chromium browser container to achieve code execution on the host system.

Properties

ghsa_id
GHSA-q94v-v6m9-jhq9
severity
medium
summary
Duplicate Advisory: OpenClaw has an improper sandbox configuration vulnerability
cvss_score
5.3
cve_id
GHSA-q94v-v6m9-jhq9
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
true
ghsa_published
2026-03-21T03:31:13Z
source_url
https://github.com/advisories/GHSA-q94v-v6m9-jhq9
ghsa_updated
2026-03-24T19:04:41Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Initialization of a Resource with an Insecure Default

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-q94v-v6m9-jhq9 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal