<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:52:57.962546+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06158</id>
    <title>bdu:2026-06158</title>
    <updated>2026-10-04T04:52:58.013517+00:00</updated>
    <content>bdu:2026-06158</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-28480</id>
    <title>BREW-openclaw-cli-CVE-2026-28480 — OpenClaw Telegram allowlist authorization accepted mutable usernames</title>
    <updated>2026-10-04T04:52:58.013552+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Telegram allowlist authorization could match on `@username` (mutable/recyclable) instead of immutable numeric sender IDs.</p>
<p>## Impact
Operators who treat Telegram allowlists as strict identity controls could unintentionally grant access if a username changes hands (identity rebinding/spoof risk). This can allow an unauthorized sender to interact with the bot in allowlist mode.</p>
<p>## Affected Packages / Versions
- npm `openclaw`: &lt;= 2026.2.13
- npm `clawdbot`: &lt;= 2026.1.24-3</p>
<p>## Fix
Telegram allowlist authorization now requires numeric Telegram sender IDs only. `@username` allowlist principals are rejected.</p>
<p>A security audit warning was added to flag legacy configs that still contain non-numeric Telegram allowlist entries.</p>
<p>`openclaw doctor --fix` now attempts to resolve `@username` allowFrom entries to numeric IDs (best-effort; requires a Telegram bot token).</p>
<p>## Fix Commit(s)
- e3b432e481a96b8fd41b91273818e514074e05c3
- 9e147f00b48e63e7be6964e0e2a97f2980854128</p>
<p>Thanks @vincentkoc for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-28480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-13544</id>
    <title>cnvd-2026-13544</title>
    <updated>2026-10-04T04:52:58.013597+00:00</updated>
    <content>cnvd-2026-13544</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-13544"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275144</id>
    <title>EUVD-2026-275144</title>
    <updated>2026-10-04T04:52:58.013612+00:00</updated>
    <content>EUVD-2026-275144</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28480</id>
    <title>fkie_cve-2026-28480</title>
    <updated>2026-10-04T04:52:58.013623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mj5r-hh7j-4gxf</id>
    <title>GHSA-mj5r-hh7j-4gxf — OpenClaw Telegram allowlist authorization accepted mutable usernames</title>
    <updated>2026-10-04T04:52:58.013645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw, npm: clawdbot</p>
<p>## Summary
Telegram allowlist authorization could match on `@username` (mutable/recyclable) instead of immutable numeric sender IDs.</p>
<p>## Impact
Operators who treat Telegram allowlists as strict identity controls could unintentionally grant access if a username changes hands (identity rebinding/spoof risk). This can allow an unauthorized sender to interact with the bot in allowlist mode.</p>
<p>## Affected Packages / Versions
- npm `openclaw`: &lt;= 2026.2.13
- npm `clawdbot`: &lt;= 2026.1.24-3</p>
<p>## Fix
Telegram allowlist authorization now requires numeric Telegram sender IDs only. `@username` allowlist principals are rejected.</p>
<p>A security audit warning was added to flag legacy configs that still contain non-numeric Telegram allowlist entries.</p>
<p>`openclaw doctor --fix` now attempts to resolve `@username` allowFrom entries to numeric IDs (best-effort; requires a Telegram bot token).</p>
<p>## Fix Commit(s)
- e3b432e481a96b8fd41b91273818e514074e05c3
- 9e147f00b48e63e7be6964e0e2a97f2980854128</p>
<p>Thanks @vincentkoc for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mj5r-hh7j-4gxf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</id>
    <title>WID-SEC-W-2026-0424 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:52:58.013676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424"/>
  </entry>
</feed>
