PT-2026-25453 · Npm · Openclaw
Publicado
2026-03-03
·
Atualizado
2026-03-03
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
The shell environment fallback path could invoke an attacker-controlled shell when
SHELL was inherited from an untrusted host environment. In affected builds, shell-env loading used $SHELL -l -c 'env -0' without validating that SHELL points to a trusted executable.In threat-model terms, this requires local environment compromise or untrusted startup environment injection first; it is not a remote pre-auth path. The hardening patch validates
SHELL as an absolute normalized executable, prefers /etc/shells, applies trusted-prefix fallback checks, and falls back safely to /bin/sh when validation fails. The dangerous env-var policy now also blocks SHELL overrides.Affected Packages / Versions
- Package:
openclaw(npm) - Affected versions:
<= 2026.2.21-2 - Latest published vulnerable version:
2026.2.21-2 - Patched versions (planned next release):
>= 2026.2.22
Fix Commit(s)
25e89cc86338ef475d26be043aa541dfdb95e52a
Release Process Note
The advisory pre-sets
patched versions to the planned next release (2026.2.22). After that npm release is published, maintainers can publish this advisory without further version-field edits.OpenClaw thanks @athuljayaram for reporting.
Correção
Untrusted Search Path
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw