{"id":"GHSA-h3rm-6x7g-882f","summary":"OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts","details":"### Summary\nIn `openclaw@2026.3.1`, node `system.run` approval-path hardening rewrote wrapper command argv in a way that changed execution semantics. A command shown/approved as a shell payload (for example `echo SAFE`) could execute a different local script when wrapper argv were rewritten.\n\n### Affected Packages / Versions\n- Package: `openclaw` (npm)\n- Affected: `2026.3.1` (latest published npm version as of March 2, 2026)\n- Fixed release: `2026.3.2` (released)\n\n### Technical Details\nRoot cause was in node-host approval hardening for `system.run`:\n- `src/node-host/invoke-system-run-plan.ts` rewrote `argv[0]` to the resolved executable.\n- Wrapper resolution unwrapped dispatch wrappers, so input like `['env','sh','-c','echo SAFE']` resolved executable `sh`.\n- The approved plan could become `['/bin/sh','sh','-c','echo SAFE']` while approval text remained `echo SAFE`.\n\nThat rewrite changed runtime behavior: `/bin/sh` interprets the extra `sh` positional argument as a script path, enabling execution of a local `./sh` file from approved `cwd` instead of the approved payload text.\n\n### Impact\nApproval-integrity break in `host=node` execution flow: operator-visible command text and executed behavior could diverge.\n\nExploit preconditions:\n- attacker can influence wrapper argv and place a local file in approved working directory,\n- operator grants approval for the displayed command.\n\n### Fix Commit(s)\n- `dded569626b0d8e7bdab10b5e7528b6caf73a0f1`\n\n### Fixed Version\n- Patched in `openclaw@2026.3.2`.","aliases":["CVE-2026-29608"],"modified":"2026-03-19T21:41:21.144916Z","published":"2026-03-03T21:19:08Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-03T21:19:08Z","nvd_published_at":null,"cwe_ids":["CWE-88"]},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-h3rm-6x7g-882f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29608"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/dded569626b0d8e7bdab10b5e7528b6caf73a0f1"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/openclaw-approval-integrity-bypass-via-system-run-argv-rewriting"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2026.3.1"},{"fixed":"2026.3.2"}]}],"versions":["2026.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-h3rm-6x7g-882f/GHSA-h3rm-6x7g-882f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}