highVulnerability

GHSA-w9cg-v44m-4qv8

### Summary `BASH_ENV` / `ENV` startup-file injection could lead to unintended pre-command shell execution when attacker-controlled environment values were admitted and then inherited by host command execution paths. ### Affected Packages / Versions - Package: `openclaw` (npm) - Affected: `<= 2026.2.19-2` - Fixed on `main`: `2cdbadee1f8fcaa93302d7debbfc529e19868ea4` - Planned patched release version: `2026.2.21` ### Details The fix hardens environment handling across all relevant execution paths: - Blocks dangerous startup/runtime env keys and prefixes in shared host env sanitization. - Sanitizes inherited ambient environment even when no per-request overrides are provided. - Blocks dangerous config-driven env injection before values enter process environment. - Uses the same sanitizer in macOS host execution paths. - Aligns skill env override sanitization with the shared dangerous-env policy. ### Impact Medium. Exploitation requires local/privileged influence over configuration or environment inputs; there is no standalone remote unauthenticated trigger from this issue alone. ### Fix Commit(s) - `2cdbadee1f8fcaa93302d7debbfc529e19868ea4` ### Release Process Note `patched_versions` is pre-set to the planned next release (`2026.2.21`). Once npm `[email protected]` is published, the advisory can be published without further field edits. OpenClaw thanks @tdjackey for reporting.

Properties

ghsa_id
GHSA-w9cg-v44m-4qv8
severity
high
summary
OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands
cve_id
GHSA-w9cg-v44m-4qv8
is_ghsa_only
true
ghsa_published
2026-03-03T22:09:52Z
source_url
https://github.com/advisories/GHSA-w9cg-v44m-4qv8
ghsa_updated
2026-03-03T22:09:53Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
[Weakness]External Control of System or Configuration Setting

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph