GHSA-m6rx-7pvw-2f73 is a high-severity (CVSS 8.4) vulnerability in @gitlawb/openclaude. O3 Security confirms whether GHSA-m6rx-7pvw-2f73 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal
Real-World Exposure
@gitlawb/openclaudeReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects npm packages — download data is not available via public APIs for these ecosystems.
Description
A logic flaw exists in bashToolHasPermission() inside src/tools/BashTool/bashPermissions.ts. When the sandbox auto-allow feature is active and no explicit deny rule is configured, the function returns an allow result immediately — before the path constraint filter (checkPathConstraints) is ever evaluated. This allows commands containing path traversal sequences (e.g., ../../../../../etc/passwd) to bypass directory restrictions entirely.
Affected Component
- File:
src/tools/BashTool/bashPermissions.ts - Function:
bashToolHasPermission - Location: ~line 1445 (sandbox auto-allow block)
Vulnerable Code Flow
bashToolHasPermission()
│
├─ [~1445] Sandbox auto-allow block
│ └─ No deny rule found → return ALLOW ⚠️ Early exit
│
└─ [~1644] checkPathConstraints() ❌ Never reached
The sandbox block was designed to skip interactive permission prompts in sandboxed environments. However, it unintentionally also skips the path traversal filter, which is a separate and critical security control.
Impact
Any process or user operating in a sandboxed session with no explicit deny rules can:
- Read arbitrary files outside the sandbox boundary (e.g.,
/etc/passwd,/etc/shadow,.envfiles, SSH private keys) - Write to arbitrary paths (subject to OS-level permissions)
- Fully defeat the filesystem isolation that the sandbox is intended to enforce
Steps to Reproduce
- Enable sandbox mode:
SandboxManager.isSandboxingEnabled() = true - Enable auto-allow:
SandboxManager.isAutoAllowBashIfSandboxedEnabled() = true - Ensure no explicit deny rules are configured for the session
- Submit a bash command with a path traversal payload:
cat ../../../../../etc/passwd - Observe that the command receives
behavior: allowwithout triggeringcheckPathConstraints
Recommended Fix
The sandbox auto-allow block should never short-circuit the full permission pipeline. It may suppress interactive prompts, but path constraint validation must always execute.
Option 1 — Preferred: Continue pipeline on allow
Only return early for deny or ask behaviors. Let allow fall through to checkPathConstraints:
if (
SandboxManager.isSandboxingEnabled() &&
SandboxManager.isAutoAllowBashIfSandboxedEnabled() &&
shouldUseSandbox(input)
) {
const sandboxAutoAllowResult = checkSandboxAutoAllow(
input,
appState.toolPermissionContext,
);
if (sandboxAutoAllowResult.behavior !== 'allow') {
// Only block or prompt — never skip path checks on allow
return sandboxAutoAllowResult;
}
// If 'allow', continue to checkPathConstraints below
}
Option 2 — Defense in depth: Run path check before returning
Run checkPathConstraints explicitly inside the sandbox block before returning:
if (sandboxAutoAllowResult.behavior !== 'passthrough') {
const pathCheck = checkPathConstraints(input, appState.toolPermissionContext);
if (pathCheck.behavior !== 'allow') {
return pathCheck; // Block traversal attempts even in sandbox
}
return sandboxAutoAllowResult;
}
Option 3 — Minimal change: Move sandbox block after path check
Reorder the function so checkPathConstraints always runs first, and the sandbox block only handles the prompt-suppression logic afterward.
Credit: Elvin Latifli (@Rickidevs )
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | @gitlawb/openclaude | all versions | 0.5.1 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @gitlawb/openclaude. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update @gitlawb/openclaude to 0.5.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-m6rx-7pvw-2f73 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether GHSA-m6rx-7pvw-2f73 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to GHSA-m6rx-7pvw-2f73. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is GHSA-m6rx-7pvw-2f73 in your dependencies?
O3 detects GHSA-m6rx-7pvw-2f73 across npm dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.