GHSA-48wf-g7cp-gr3m: OpenClaw has allowlist exec-guard bypass via env -S
In allowlist mode, system.run guardrails could be bypassed through env -S, causing policy-analysis/runtime-execution mismatch for shell wrapper payloads.
References
Code Behaviors & Features
Detect and mitigate GHSA-48wf-g7cp-gr3m with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →