highCVSS 7.1Vulnerability

GHSA-w8rf-7qf8-65ww

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-rw39-5899-8mxp. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.

Properties

ghsa_id
GHSA-w8rf-7qf8-65ww
summary
Duplicate Advisory: OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
severity
high
cvss_score
7.1
cve_id
GHSA-w8rf-7qf8-65ww
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-03-31T12:31:35Z
source_url
https://github.com/advisories/GHSA-w8rf-7qf8-65ww
ghsa_updated
2026-04-06T22:37:24Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]User Interface (UI) Misrepresentation of Critical Information

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph