GHSA-659f-22xc-98f2: OpenClaw hook transform path containment missed symlink-resolved escapes
When an attacker can cause a transform module path to reference a symlinked entry that resolves outside the trusted transform directory, the gateway may import and execute unintended JavaScript with gateway-process privileges.
References
Code Behaviors & Features
Detect and mitigate GHSA-659f-22xc-98f2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →