GHSA-82g8-464f-2mv7: OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
(updated )
applySkillConfigEnvOverrides previously copied skills.entries.*.env values into the host process.env without applying the host env safety policy.
References
Code Behaviors & Features
Detect and mitigate GHSA-82g8-464f-2mv7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →