Dismissed
by @mweinelt Activity log
- Created automatic suggestion
- @mweinelt dismissed
OpenClaw 2026.2.15 - Option Injection in pre-commit Hook via Malicious Filenames
OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named files beginning with dashes. The hook fails to use a -- separator when piping filenames through xargs to git add, enabling attackers to inject git flags and add sensitive ignored files like .env to git history.
References
-
Patch Commit #1 patch
-
Patch Commit #2 patch
-
GitHub Security Advisory (GHSA-mmpf-jwf4-h3qv) vendor-advisory
Affected products
OpenClaw
- <2026.2.15
Package maintainers
-
@chrisportela Chris Portela <chris@chrisportela.com>