PT-2026-25100 · Npm · Openclaw
Published
2026-03-02
·
Updated
2026-03-02
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Summary
A paired node could supply Unicode-confusable
platform or deviceFamily metadata that passed metadata pinning but classified differently for command policy resolution, broadening default node command allowlists.Impact
This is a policy-bypass issue within the paired-node trust boundary and can expand node command availability beyond intended defaults.
Fix
Node metadata canonicalization was hardened against confusables, and unknown platform defaults were made conservative (excluding
system.run and system.which unless explicitly allowlisted).Affected and Patched Versions
- Affected:
<= 2026.2.26 - Patched:
2026.3.1
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw