Description
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can execute unintended local package-manager executables during dependency setup to compromise the build environment.
Problem types
Product status
Any version before 2026.4.29
2026.4.29 (semver)
Credits
侯海飞 (@feynman-hou)
References
github.com/...enclaw/security/advisories/GHSA-24vr-rprv-67rf (GitHub Security Advisory (GHSA-24vr-rprv-67rf))
www.vulncheck.com/...xecution-via-workspace-env-npm-execpath (VulnCheck Advisory: OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpath)