PT-2026-25437 · Npm · Openclaw

Publicado

2026-03-03

·

Atualizado

2026-03-03

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Summary

The tar.bz2 installer path in src/agents/skills-install-download.ts used shell tar preflight/extract logic that did not share the same hardening guarantees as the centralized archive extractor.
This allowed crafted .tar.bz2 archives to bypass special-entry blocking and extracted-size guardrails enforced on other archive paths, causing local availability impact during skill install.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published at triage time: 2026.3.1
  • Affected range: <= 2026.3.1
  • Patched in: 2026.3.2 (released)

Impact

Local DoS / availability impact when processing untrusted .tar.bz2 skill archives.

Fix Commit(s)

  • 0dbb92dd2bcf9a32379d11c0f11ed016669dae3e

Related advisories

  • Canonical overlap (closed): GHSA-3pj7-x8jr-jvj8
  • Duplicate variant (closed): GHSA-rgr7-g85h-6v82

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-77HF-7FQF-F227

Produtos afetados

Openclaw