GHSA-gj9q-8w99-mp8j: OpenClaw: TOCTOU read in exec script preflight
OpenClaw’s exec script preflight validator previously validated and then read a script by mutable pathname. A local race could swap the path between validation and read, causing preflight analysis to inspect a different file identity than the one that passed the workspace boundary check.
References
Code Behaviors & Features
Detect and mitigate GHSA-gj9q-8w99-mp8j with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →