<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:01:24.076730+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-28448</id>
    <title>BREW-openclaw-cli-CVE-2026-28448 — OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline</title>
    <updated>2026-10-04T00:01:24.140086+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary</p>
<p>In the optional Twitch channel plugin (`extensions/twitch`), `allowFrom` is documented as a hard allowlist of Twitch user IDs, but it was not enforced as a hard gate. If `allowedRoles` is unset or empty, the access control path defaulted to allow, so any Twitch user who could mention the bot could reach the agent dispatch pipeline.</p>
<p>**Scope note:** This only affects deployments that installed and enabled the Twitch plugin. Core OpenClaw installs that do not install/enable the Twitch plugin are not impacted.</p>
<p>### Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected: `&gt;= 2026.1.29, &lt; 2026.2.1`
- Fixed: `&gt;= 2026.2.1`</p>
<p>### Details</p>
<p>Affected component: Twitch plugin access control (`extensions/twitch/src/access-control.ts`).</p>
<p>Problematic logic in `checkTwitchAccessControl()`:</p>
<p>- When `allowFrom` was configured, the code returned `allowed: true` for members but did not return `allowed: false` for non-members, so execution fell through.
- If `allowedRoles` was unset or empty, the function returned `allowed: true` by default, even when `allowFrom` was configured.</p>
<p>### Proof of Concept (PoC)</p>
<p>1. Install and enable the Twitch plugin.
2. Configure an `allowFrom` list, but do not set `allowedRoles` (or set it to an empty list).
3. From a different Twitch account whose user ID is NOT in `allowFrom`, send a message that mentions the bot (for example `@&lt;botname&gt; hello`).
4. Observe the message is processed and can trigger agent dispatch/replies despite not bein…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-28448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275195</id>
    <title>EUVD-2026-275195</title>
    <updated>2026-10-04T00:01:24.140165+00:00</updated>
    <content>EUVD-2026-275195</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28448</id>
    <title>fkie_cve-2026-28448</title>
    <updated>2026-10-04T00:01:24.140182+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twitch users to trigger agent dispatch. Remote attackers can mention the bot in Twitch chat to bypass access control and invoke the agent pipeline, potentially causing unintended actions or resource exhaustion.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-33rq-m5x2-fvgf</id>
    <title>GHSA-33rq-m5x2-fvgf — OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline</title>
    <updated>2026-10-04T00:01:24.140208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>### Summary</p>
<p>In the optional Twitch channel plugin (`extensions/twitch`), `allowFrom` is documented as a hard allowlist of Twitch user IDs, but it was not enforced as a hard gate. If `allowedRoles` is unset or empty, the access control path defaulted to allow, so any Twitch user who could mention the bot could reach the agent dispatch pipeline.</p>
<p>**Scope note:** This only affects deployments that installed and enabled the Twitch plugin. Core OpenClaw installs that do not install/enable the Twitch plugin are not impacted.</p>
<p>### Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected: `&gt;= 2026.1.29, &lt; 2026.2.1`
- Fixed: `&gt;= 2026.2.1`</p>
<p>### Details</p>
<p>Affected component: Twitch plugin access control (`extensions/twitch/src/access-control.ts`).</p>
<p>Problematic logic in `checkTwitchAccessControl()`:</p>
<p>- When `allowFrom` was configured, the code returned `allowed: true` for members but did not return `allowed: false` for non-members, so execution fell through.
- If `allowedRoles` was unset or empty, the function returned `allowed: true` by default, even when `allowFrom` was configured.</p>
<p>### Proof of Concept (PoC)</p>
<p>1. Install and enable the Twitch plugin.
2. Configure an `allowFrom` list, but do not set `allowedRoles` (or set it to an empty list).
3. From a different Twitch account whose user ID is NOT in `allowFrom`, send a message that mentions the bot (for example `@&lt;botname&gt; hello`).
4. Observe the message is processed and can trigger agent dispatch/replies despite not bein…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-33rq-m5x2-fvgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</id>
    <title>WID-SEC-W-2026-0424 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:01:24.140248+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424"/>
  </entry>
</feed>
