{"id":"GHSA-ff98-w8hj-qrxf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-ff98-w8hj-qrxf","summary":"OpenClaw plugin runtime command execution is part of trusted plugin boundary","details":"### Summary\nOpenClaw plugins/extensions run in-process and are treated as trusted code. This advisory tracks trust-boundary clarification around plugin runtime command execution (`runtime.system.runCommandWithTimeout`).\n\n### Impact\nPlugins already execute with the same OS privileges as the OpenClaw process. Exposing runtime command helpers does not cross an additional sandbox boundary.\n\n### Affected Packages / Versions\n- Package: `openclaw` (npm)\n- Latest published version reviewed: `2026.2.17`\n- Affected range for this advisory record: `<= 2026.2.17`\n- Planned patched version metadata: `2026.2.19` (next release line)\n\n### Fix Commit(s)\n- `2e421f32dfc589c02706265fd3c3137ffc06c4b1`\n\n### Remediation\n- Install only trusted plugins.\n- Use `plugins.allow` to pin explicit trusted plugin IDs.\n- SECURITY.md now explicitly documents that plugin runtime helpers are convenience APIs, not a sandbox boundary.\n\nOpenClaw thanks @markmusson for reporting.","published":"2026-03-03T21:39:26Z","modified":"2026-03-04T15:14:30.313185Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.19"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/2e421f32dfc589c02706265fd3c3137ffc06c4b1","label":"openclaw/openclaw@2e421f3"},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-ff98-w8hj-qrxf"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/2e421f32dfc589c02706265fd3c3137ffc06c4b1"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-04T15:14:30.313185Z"}}