GHSA-qhrr-grqp-6x2g: OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode
In openclaw allowlist mode, tools.exec.safeBins trusted PATH-derived directories for safe-bin resolution. A same-name binary placed in a trusted PATH directory could satisfy safe-bin checks and execute.
References
Code Behaviors & Features
Detect and mitigate GHSA-qhrr-grqp-6x2g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →