{"id":"GHSA-f8r2-vg7x-gh8m","summary":"OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths","details":"### Summary\n\n`matchesExecAllowlistPattern` normalized patterns and targets with lowercasing and compiled glob matching too broadly on POSIX. In addition, the `?` wildcard could match `/`, which allowed matches to cross path segments.\n\n### Impact\n\nThese matching rules could overmatch allowlist entries and permit commands or executable paths that an operator did not intend to approve.\n\n### Affected versions\n\n`openclaw` `\u003c= 2026.3.8`\n\n### Patch\n\nFixed in `openclaw` `2026.3.11` and included in later releases such as `2026.3.12`. Exec allowlist matching now respects the intended path semantics, and regression tests cover the POSIX case-folding and slash-crossing cases.","aliases":["CVE-2026-32973"],"modified":"2026-07-08T07:35:46.370111113Z","published":"2026-03-13T20:55:03Z","database_specific":{"cwe_ids":["CWE-178","CWE-625"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-13T20:55:03Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-f8r2-vg7x-gh8m"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/releases/tag/v2026.3.11"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.3.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-f8r2-vg7x-gh8m/GHSA-f8r2-vg7x-gh8m.json","last_known_affected_version_range":"\u003c= 2026.3.8"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}