GHSA-gfmx-pph7-g46x: openclaw: trust boundary bypass enables prompt injection
GHSA-gfmx-pph7-g46x HIGHA trust boundary violation in OpenClaw's async event pipeline allows lower-privilege background runtime output to be promoted into trusted System-level events, enabling prompt injection into subsequent agent turns without any visible trace in the user-facing conversation. This matters beyond the advisory's local-only framing because OpenClaw's third-party skills ecosystem has documented active abuse — AIID #1368 reports approximately 17% of skills assessed as malicious, with credential-stealing payloads already observed in the wild — meaning a compromised skill could chain this flaw to escalate from sandboxed background execution to full system-level instruction authority over the agent. The package's history of 41 prior CVEs signals a persistent security posture problem, not an isolated incident. Patch immediately to openclaw 2026.4.8; if upgrade is not immediately possible, disable all third-party skills and audit installed ones against a trusted allowlist.
What is the risk?
HIGH. Although scoped to local user-controlled deployments rather than multi-tenant infrastructure, the trust boundary violation directly enables a prompt injection escalation primitive — one of the highest-impact attack classes in agentic AI systems. CWE-501 in an async event handler is particularly dangerous because the injection is invisible to the user: it appears as a system-level instruction in a channel the user cannot inspect. The documented malicious skills ecosystem (AIID #1368) elevates exploitation likelihood substantially above theoretical, as a ready-made delivery mechanism already exists. No EPSS data or CVSS vector is available, but the combination of an exploitable delivery channel, a weaponizable trust escalation bug, and a package with 41 prior CVEs warrants treating exploitation as active until proven otherwise.
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| openclaw | npm | <= 2026.4.2 | 2026.4.8 |
Do you use openclaw? You're affected.
Severity & Risk
What should I do?
5 steps-
Upgrade to openclaw >= 2026.4.8 immediately — the fix is on npm and was regression-tested against the specific trust boundary logic.
-
If upgrade is blocked: disable all third-party and unverified skills; restrict OpenClaw to first-party or explicitly audited skills only.
-
Audit installed skills against a trusted allowlist; cross-reference against AIID #1368 for known-malicious skill indicators (AMOS stealer delivery, credential exfiltration patterns).
-
Review stored agent conversation logs and command histories for unexpected System-level instruction sequences that could indicate prior exploitation.
-
Subscribe to the OpenClaw GitHub advisory feed given the package's 41-CVE track record — treat future advisories as high priority.
Classification
Compliance Impact
This CVE is relevant to:
Related AI Incidents (1)
Source: AI Incident Database (AIID)
Frequently Asked Questions
What is GHSA-gfmx-pph7-g46x?
A trust boundary violation in OpenClaw's async event pipeline allows lower-privilege background runtime output to be promoted into trusted System-level events, enabling prompt injection into subsequent agent turns without any visible trace in the user-facing conversation. This matters beyond the advisory's local-only framing because OpenClaw's third-party skills ecosystem has documented active abuse — AIID #1368 reports approximately 17% of skills assessed as malicious, with credential-stealing payloads already observed in the wild — meaning a compromised skill could chain this flaw to escalate from sandboxed background execution to full system-level instruction authority over the agent. The package's history of 41 prior CVEs signals a persistent security posture problem, not an isolated incident. Patch immediately to openclaw 2026.4.8; if upgrade is not immediately possible, disable all third-party skills and audit installed ones against a trusted allowlist.
Is GHSA-gfmx-pph7-g46x actively exploited?
No confirmed active exploitation of GHSA-gfmx-pph7-g46x has been reported, but organizations should still patch proactively.
How to fix GHSA-gfmx-pph7-g46x?
1. Upgrade to openclaw >= 2026.4.8 immediately — the fix is on npm and was regression-tested against the specific trust boundary logic. 2. If upgrade is blocked: disable all third-party and unverified skills; restrict OpenClaw to first-party or explicitly audited skills only. 3. Audit installed skills against a trusted allowlist; cross-reference against AIID #1368 for known-malicious skill indicators (AMOS stealer delivery, credential exfiltration patterns). 4. Review stored agent conversation logs and command histories for unexpected System-level instruction sequences that could indicate prior exploitation. 5. Subscribe to the OpenClaw GitHub advisory feed given the package's 41-CVE track record — treat future advisories as high priority.
What systems are affected by GHSA-gfmx-pph7-g46x?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, local AI assistants, AI agent tool ecosystems.
What is the CVSS score for GHSA-gfmx-pph7-g46x?
No CVSS score has been assigned yet.
AI Security Impact
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0010.005 AI Agent Tool AML.T0051 LLM Prompt Injection AML.T0051.001 Indirect AML.T0080 AI Agent Context Poisoning AML.T0080.001 Thread Compliance Controls Affected
Technical Details
Original Advisory
## Impact Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade. Lower-trust runtime/background output could be promoted into trusted System events, allowing prompt-injection into later agent turns. OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant service boundary. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.4.2` - Patched versions: `2026.4.8` ## Fix The issue was fixed on `main` and is available in the patched npm version listed above. The verified fixed tree is commit `d7c3210cd6f5fdfdc1beff4c9541673e814354d5`. ## Verification The fix was re-checked against `main` before publication, including targeted regression tests for the affected security boundary. ## Credits Thanks @tdjackey for reporting.
Exploitation Scenario
An adversary publishes a skill to ClawHub that appears legitimate but includes a background task that spawns an async exec operation. The skill is installed by an end user. During normal operation, the skill's background task completes and its output — crafted as a prompt injection payload instructing the agent to exfiltrate stored credentials or API tokens — is processed by OpenClaw's async completion handler. Because the exec-event downgrade is not applied, the output is promoted into a trusted System: event before the next agent turn. The agent, believing it is following system-level instructions, silently executes the adversary's commands. The injection never appears in the user-visible conversation thread, and no explicit user confirmation is required, making detection without log analysis essentially impossible.
Weaknesses (CWE)
References
Timeline
Related Vulnerabilities
CVE-2026-30741 9.8 OpenClaw: RCE via request-side prompt injection
Same package: openclaw CVE-2026-28451 9.3 OpenClaw: SSRF via Feishu extension exposes internal services
Same package: openclaw GHSA-cwj3-vqpp-pmxr 8.8 openclaw: Model bypasses authz to persist unsafe config
Same package: openclaw GHSA-m3mh-3mpg-37hw 8.6 OpenClaw: .npmrc hijack enables RCE on plugin install
Same package: openclaw CVE-2026-27001 7.8 OpenClaw: prompt injection via unsanitized workspace path
Same package: openclaw