GHSA-j7p2-qcwm-94v4: OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
Host exec env override sanitization did not fail closed for several package-manager and related redirect variables that can steer dependency fetches or startup behavior.
References
Code Behaviors & Features
Detect and mitigate GHSA-j7p2-qcwm-94v4 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →