Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 npm

GHSA-796m-2973-wc5q

GHSA-796m-2973-wc5q is a security vulnerability in openclaw. O3 Security confirms whether GHSA-796m-2973-wc5q is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation

Published
Mar 3, 2026
Updated
Mar 4, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed

Blast Radius

1 pkg affected

Weekly download volume for affected packages — a proxy for how broadly this vulnerability is deployed.

openclawnpm
3.1Mdownloads / week

Description

Summary

tools.exec allowlist/safe-bins evaluation could diverge from runtime execution for wrapper commands using GNU env -S/--split-string semantics. This allowed policy checks to treat a command as a benign safe-bin invocation while runtime executed a different payload.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Vulnerable versions: <= 2026.2.22-2 (latest currently published npm version)
  • Patched version (released): 2026.2.23

Impact

An attacker able to influence tool command text (for example via untrusted prompt/content injection reaching an exec-capable flow) could bypass allowlist/safe-bins intent and execute unexpected commands.

Technical Details

Root cause was policy/runtime interpretation mismatch for dispatch wrappers:

  • analysis resolved an effective executable from wrapper-unwrapped argv,
  • execution could still run original wrapper argv semantics,
  • safe-bin short-flag handling also allowed unknown short options in clusters.

Remediation

The fix hardens exec approvals to fail closed and enforce analysis/runtime parity:

  • introduce wrapper execution planning with semantic-wrapper blocking,
  • carry planned effectiveArgv + policyBlocked metadata through resolution,
  • evaluate allowlist/safe-bins against planned argv,
  • enforce canonical rebuilt shell command from planned argv for allowlist auto-paths,
  • use planned argv for node-host/mac exec-host invocation paths,
  • reject unknown short safe-bin flags,
  • add regression tests for semantic env wrappers and parity fixtures.

Fix Commit(s)

  • a1c4bf07c6baad3ef87a0e710fe9aef127b1f606

Release Process Note

patched_versions is pre-set to the released version (2026.2.23). Patched in 2026.2.23 and published.

OpenClaw thanks @jiseoung for reporting.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npmopenclawall versions2026.2.23

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for openclaw. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update openclaw to 2026.2.23 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-796m-2973-wc5q is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-796m-2973-wc5q is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-796m-2973-wc5q. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Summary `tools.exec` allowlist/safe-bins evaluation could diverge from runtime execution for wrapper commands using GNU `env -S/--split-string` semantics. This allowed policy checks to treat a command as a benign safe-bin invocation while runtime executed a different payload. ### Affected Packages / Versions - Package: `openclaw` (npm) - Vulnerable versions: `<= 2026.2.22-2` (latest currently published npm version) - Patched version (released): `2026.2.23` ### Impact An attacker able to influence tool command text (for example via untrusted prompt/content injection reaching an exec-capab
O3 Security · Impact-Aware SCA

Is GHSA-796m-2973-wc5q in your dependencies?

O3 detects GHSA-796m-2973-wc5q across npm dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.