Skip to content

OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)

High severity GitHub Reviewed Published Feb 15, 2026 in openclaw/openclaw • Updated Feb 18, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts