GHSA-2rqg-gjgv-84jm: OpenClaw: Gateway `agent` calls could override the workspace boundary
The public gateway agent RPC allowed an authenticated operator with operator.write to supply attacker-controlled spawnedBy and workspaceDir values. That let the caller re-root the agent run outside its configured workspace boundary.
References
Code Behaviors & Features
Detect and mitigate GHSA-2rqg-gjgv-84jm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →