GHSA-2w22-3f6x-3hf4High· 7.1▾ TwilightDuplicate Advisory: Workspace-derived service PATH could influence trash command selection
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-rx78-29qr-5hq8. This link is maintained to preserve external references.
OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operator-unintended paths during maintenance operations by manipulating workspace-derived environment paths.
openclaw < 2026.5.2Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53865High· 7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
CVE-2026-53819High· 8.8OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
GHSA-qp5j-jr73-m2pwHigh· 7.1Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install
GHSA-4qgr-57jq-93vhHigh· 7.1Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
CVE-2026-53842High· 7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-53846High· 7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install