mediumCVSS 6.3Vulnerability

GHSA-wgx8-r9vw-2w4h

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-82g8-464f-2mv7. This link is maintained to preserve external references. ### Original Description A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. Upgrading to version 2026.2.21-beta.1 is able to resolve this issue. This patch is called 8c9f35cdb51692b650ddf05b259ccdd75cc9a83c. It is recommended to upgrade the affected component.

Properties

ghsa_id
GHSA-wgx8-r9vw-2w4h
severity
medium
summary
Duplicate Advisory: OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
cvss_score
6.3
cve_id
GHSA-wgx8-r9vw-2w4h
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
true
ghsa_published
2026-03-12T12:30:29Z
source_url
https://github.com/advisories/GHSA-wgx8-r9vw-2w4h
ghsa_updated
2026-03-12T17:30:15Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-wgx8-r9vw-2w4h (CVSS 6.3) — Ninja Signal Threat Intelligence | Ninja Signal