GHSA-w9cg-v44m-4qv8
### Summary `BASH_ENV` / `ENV` startup-file injection could lead to unintended pre-command shell execution when attacker-controlled environment values were admitted and then inherited by host command execution paths. ### Affected Packages / Versions - Package: `openclaw` (npm) - Affected: `<= 2026.2.19-2` - Fixed on `main`: `2cdbadee1f8fcaa93302d7debbfc529e19868ea4` - Planned patched release version: `2026.2.21` ### Details The fix hardens environment handling across all relevant execution paths: - Blocks dangerous startup/runtime env keys and prefixes in shared host env sanitization. - Sanitizes inherited ambient environment even when no per-request overrides are provided. - Blocks dangerous config-driven env injection before values enter process environment. - Uses the same sanitizer in macOS host execution paths. - Aligns skill env override sanitization with the shared dangerous-env policy. ### Impact Medium. Exploitation requires local/privileged influence over configuration or environment inputs; there is no standalone remote unauthenticated trigger from this issue alone. ### Fix Commit(s) - `2cdbadee1f8fcaa93302d7debbfc529e19868ea4` ### Release Process Note `patched_versions` is pre-set to the planned next release (`2026.2.21`). Once npm `[email protected]` is published, the advisory can be published without further field edits. OpenClaw thanks @tdjackey for reporting.
Properties
- ghsa_id
- GHSA-w9cg-v44m-4qv8
- severity
- high
- summary
- OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands
- cve_id
- GHSA-w9cg-v44m-4qv8
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T22:09:52Z
- source_url
- https://github.com/advisories/GHSA-w9cg-v44m-4qv8
- ghsa_updated
- 2026-03-03T22:09:53Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph