GHSA-xf99-j42q-5w5p: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
In affected versions of openclaw, node-host system.run approvals could still execute rewritten local code for interpreter and runtime commands when OpenClaw could not bind exactly one concrete local file operand during approval planning.
References
Code Behaviors & Features
Detect and mitigate GHSA-xf99-j42q-5w5p with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →