GHSA-qp5j-jr73-m2pwHigh· 7.1▾ TwilightDuplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-24vr-rprv-67rf. This link is maintained to preserve external references.
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can execute unintended local package-manager executables during dependency setup to compromise the build environment.
openclaw < 2026.4.29Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53846High· 7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
CVE-2026-53819High· 8.8OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
GHSA-4qgr-57jq-93vhHigh· 7.1Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
GHSA-2w22-3f6x-3hf4High· 7.1Duplicate Advisory: Workspace-derived service PATH could influence trash command selection
CVE-2026-53842High· 7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-53858High· 7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots