Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
HIGH severity

GHSA-mhq8-78pj-5j79 — openclaw

HIGH

GHSA-mhq8-78pj-5j79 is a high-severity (CVSS 7.1) CWE-367 vulnerability in openclaw. A fix is available for openclaw — see the affected versions and patch details below.

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

Also known asCVE-2026-53831
Published
Jul 2, 2026
Updated
Aug 26, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-mhq8-78pj-5j79.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk+0.13%
Lower risk than most CVEs23th percentile — riskier than 23% of all scored CVEsHighest risk
0.00%0.28%0.55%0.83%0.2%0.3%Sep 26Sep 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

GHSA-mhq8-78pj-5j79 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 381,682 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

133other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
openclawnpm
3.4Mdownloads / week

Description

Summary

On POSIX nodes, OpenClaw's system.run safe-bin checks could approve a command before shell expansion changed how the command was interpreted. A value that appeared to be a safe-bin argument could expand into additional shell words and become a file operand.

This issue is limited to paired POSIX node execution through system.run with safe-bin or allowlist-style auto-approval. It is not an unauthenticated node takeover.

Affected configurations

This affects deployments where:

  • a POSIX node is paired to the gateway
  • system.run is reachable by an authenticated operator or agent flow
  • exec policy uses safe-bin or allowlist-based auto-approval
  • the approved command contains shell-expanded values that can change argv shape

Impact

A lower-privilege operator flow could cause an approved safe-bin command to read a node-local file that was not intended by the policy. Depending on the local files available to the node process, this could expose OpenClaw configuration data or other node-local information.

The issue is a policy-enforcement gap in argv validation, not a general statement that every safe-bin command is unsafe.

Patched Versions

The first stable patched version is 2026.5.18.

Mitigations

Upgrade to [email protected] or later. Before upgrading, avoid broad safe-bin auto-approval for commands that can read arbitrary paths, and prefer explicit approval for node commands that touch local files.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npmopenclawall versions2026.5.18npm install openclaw@2026.5.18

Affected Products

1 product · 1 configurations
Application
openclawopenclaw
< 2026.5.18
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for openclaw, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update openclaw to 2026.5.18 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-mhq8-78pj-5j79 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Frequently Asked Questions

### Summary On POSIX nodes, OpenClaw's `system.run` safe-bin checks could approve a command before shell expansion changed how the command was interpreted. A value that appeared to be a safe-bin argument could expand into additional shell words and become a file operand. This issue is limited to paired POSIX node execution through `system.run` with safe-bin or allowlist-style auto-approval. It is not an unauthenticated node takeover. ### Affected configurations This affects deployments where: - a POSIX node is paired to the gateway - `system.run` is reachable by an authenticated operator
O3 Security · Impact-Aware SCA

Is GHSA-mhq8-78pj-5j79 in your dependencies?

Find it across npm, including transitive dependencies.

GHSA-mhq8-78pj-5j79: openclaw (High 7.1) | O3 Security