highCVSS 8.1Vulnerability
GHSA-vr6h-vxqj-3pjx
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-ccwh-wwpp-6wg5. This link is maintained to preserve external references. ## Original Description OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.
Properties
- ghsa_id
- GHSA-vr6h-vxqj-3pjx
- summary
- Duplicate Advisory: Host environment sanitizer missed two Node.js control variables
- severity
- high
- cvss_score
- 8.1
- cve_id
- GHSA-vr6h-vxqj-3pjx
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-06-16T21:32:00Z
- source_url
- https://github.com/advisories/GHSA-vr6h-vxqj-3pjx
- ghsa_updated
- 2026-06-18T13:02:40Z
Related Entities (4)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/openclaw
AFFECTS (1)
→[Software]npm/openclaw
HAS_WEAKNESS (1)
→[Weakness]Incomplete List of Disallowed Inputs
Explore deeper with Ninja Signal's threat intelligence graph