@gitlawb/openclaude@0.5.0

OpenClaude opens coding-agent workflows to any LLM — OpenAI, Gemini, DeepSeek, Ollama, and 200+ models

  • latest version

    0.10.0

  • latest non vulnerable version

  • first published

    1 months ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @gitlawb/openclaude package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Access Control Bypass

    @gitlawb/openclaude is an OpenClaude opens coding-agent workflows to any LLM — OpenAI, Gemini, DeepSeek, Ollama, and 200+ models

    Affected versions of this package are vulnerable to Access Control Bypass via the bashToolHasPermission function. An attacker can access or modify files outside the intended sandbox boundaries by submitting commands containing path traversal sequences when the sandbox auto-allow feature is enabled and no explicit deny rules are configured. This is only exploitable if the sandbox auto-allow feature is active and there are no explicit deny rules present for the session.

    How to fix Access Control Bypass?

    Upgrade @gitlawb/openclaude to version 0.5.1 or higher.

    <0.5.1