GHSA-w9cg-v44m-4qv8: OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands
BASH_ENV / ENV startup-file injection could lead to unintended pre-command shell execution when attacker-controlled environment values were admitted and then inherited by host command execution paths.
References
Code Behaviors & Features
Detect and mitigate GHSA-w9cg-v44m-4qv8 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →