criticalCVSS 8.1Vulnerability

GHSA-rwwx-25m7-ww73

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-qc36-x95h-7j53. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, rewrite referenced scripts on disk, and execute modified code under the approved run context.

Properties

ghsa_id
GHSA-rwwx-25m7-ww73
severity
critical
summary
Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
cvss_score
8.1
cve_id
GHSA-rwwx-25m7-ww73
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-03-29T15:30:19Z
source_url
https://github.com/advisories/GHSA-rwwx-25m7-ww73
ghsa_updated
2026-04-06T22:35:51Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph