GHSA-g2f6-pwvx-r275: OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection
openclaw versions <= 2026.3.12 accepted unsanitized iMessage remote attachment paths when staging files over SCP, allowing shell metacharacters in the remote path operand.
References
Code Behaviors & Features
Detect and mitigate GHSA-g2f6-pwvx-r275 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →