GHSA-6pfc-6m7w-m8fx: OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper
Allow-always persistence did not unwrap /usr/bin/script and similar wrappers to the actual executed target before storing trust decisions.
References
Code Behaviors & Features
Detect and mitigate GHSA-6pfc-6m7w-m8fx with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →