In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade openclaw to version 2026.3.7-beta.1 or higher.
openclaw is a 🦞 OpenClaw — Personal AI Assistant
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the system.run process. An attacker can bypass intended allowlist or approval mechanisms by supplying crafted environment variable overrides such as GIT_SSH_COMMAND, GIT_CONFIG_*, or NPM_CONFIG_*, which are not properly sanitized and can influence the behavior of spawned subprocesses.