GHSA-fg3m-vhrr-8gj6: OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path
On Windows, the Lobster extension previously retried certain spawn failures (ENOENT/EINVAL) with shell: true for wrapper compatibility. In that fallback path, tool-provided arguments could be interpreted by cmd.exe if fallback was triggered.
References
Code Behaviors & Features
Detect and mitigate GHSA-fg3m-vhrr-8gj6 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →