2.8.5
4 months ago
17 days ago
Known vulnerabilities in the @axonflow/openclaw package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@axonflow/openclaw is a Policy enforcement, approval gates, and audit trails for OpenClaw — govern tool inputs before execution, scan outbound messages for PII/secrets, and record agent activity for review and compliance Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource due to improper permission settings on directories and credential files. An attacker can access sensitive registration credentials and cache state by reading files in How to fix Incorrect Permission Assignment for Critical Resource? Upgrade | <2.0.0 |