GHSA-m34q-h93w-vg5x: OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped
Before OpenClaw 2026.4.2, the OpenShell mirror backend accepted arbitrary absolute remoteWorkspaceDir and remoteAgentWorkspaceDir values. In mirror mode, those paths were then used as the target of remote cleanup and overwrite operations.
References
Code Behaviors & Features
Detect and mitigate GHSA-m34q-h93w-vg5x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →