GHSA-796m-2973-wc5q: OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation
tools.exec allowlist/safe-bins evaluation could diverge from runtime execution for wrapper commands using GNU env -S/--split-string semantics. This allowed policy checks to treat a command as a benign safe-bin invocation while runtime executed a different payload.
References
Code Behaviors & Features
Detect and mitigate GHSA-796m-2973-wc5q with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →