GHSA-xgf2-vxv2-rrmg: OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)
system.run environment sanitization allowed shell-startup env overrides (HOME, ZDOTDIR) that can execute attacker-controlled startup files before allowlist-evaluated command bodies.
References
Code Behaviors & Features
Detect and mitigate GHSA-xgf2-vxv2-rrmg with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →