openclaw/extensions
Vignesh 1295b67057
fix(lobster): block arbitrary exec via lobsterPath/cwd (GHSA-4mhr-g7xj-cg8j) (#5335)
* fix(lobster): prevent arbitrary exec via lobsterPath/cwd

* fix(lobster): harden lobsterPath errors + normalize cwd sandboxing

* fix(lobster): ignore tool-provided lobsterPath; validate + use plugin config

* fix(lobster): use plugin config lobsterPath + add tests (#5335) (thanks @vignesh07)

* fix(lobster): make Windows spawn fallback handle ENOENT (#5335) (thanks @vignesh07)

---------

Co-authored-by: Tyler Yust <TYTYYUST@YAHOO.COM>
2026-01-31 12:46:20 -08:00
..
bluebubbles chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
copilot-proxy chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
diagnostics-otel chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
discord chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
google-antigravity-auth chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
google-gemini-cli-auth chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
googlechat chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
imessage chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
line chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
llm-task chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
lobster fix(lobster): block arbitrary exec via lobsterPath/cwd (GHSA-4mhr-g7xj-cg8j) (#5335) 2026-01-31 12:46:20 -08:00
matrix chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
mattermost chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
memory-core chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
memory-lancedb chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
minimax-portal-auth chore: Add `openclaw` to `devDependencies` for all extensions so that types resolve. 2026-01-31 22:06:51 +09:00
msteams chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
nextcloud-talk chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
nostr chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
open-prose chore: Add `openclaw` to `devDependencies` for all extensions so that types resolve. 2026-01-31 22:06:51 +09:00
qwen-portal-auth chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
signal chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
slack chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
telegram chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
tlon chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
twitch chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
voice-call chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
whatsapp chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
zalo chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00
zalouser chore: Lint extensions folder. 2026-01-31 22:42:45 +09:00