PT-2026-25454 · Npm · Openclaw

Publicado

2026-03-03

·

Atualizado

2026-03-03

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Summary

OpenClaw plugins/extensions run in-process and are treated as trusted code. This advisory tracks trust-boundary clarification around plugin runtime command execution (runtime.system.runCommandWithTimeout).

Impact

Plugins already execute with the same OS privileges as the OpenClaw process. Exposing runtime command helpers does not cross an additional sandbox boundary.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published version reviewed: 2026.2.17
  • Affected range for this advisory record: <= 2026.2.17
  • Planned patched version metadata: 2026.2.19 (next release line)

Fix Commit(s)

  • 2e421f32dfc589c02706265fd3c3137ffc06c4b1

Remediation

  • Install only trusted plugins.
  • Use plugins.allow to pin explicit trusted plugin IDs.
  • SECURITY.md now explicitly documents that plugin runtime helpers are convenience APIs, not a sandbox boundary.
OpenClaw thanks @markmusson for reporting.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-FF98-W8HJ-QRXF

Produtos afetados

Openclaw