<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:00:24.708636+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32032</id>
    <title>BREW-openclaw-cli-CVE-2026-32032 — OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment</title>
    <updated>2026-10-03T14:00:24.712436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>The shell environment fallback path could invoke an attacker-controlled shell when `SHELL` was inherited from an untrusted host environment. In affected builds, shell-env loading used `$SHELL -l -c 'env -0'` without validating that `SHELL` points to a trusted executable.</p>
<p>In threat-model terms, this requires local environment compromise or untrusted startup environment injection first; it is not a remote pre-auth path. The hardening patch validates `SHELL` as an absolute normalized executable, prefers `/etc/shells`, applies trusted-prefix fallback checks, and falls back safely to `/bin/sh` when validation fails. The dangerous env-var policy now also blocks `SHELL` overrides.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.2.21-2`
- Latest published vulnerable version: `2026.2.21-2`
- Patched versions (planned next release): `&gt;= 2026.2.22`</p>
<p>## Fix Commit(s)
- `25e89cc86338ef475d26be043aa541dfdb95e52a`</p>
<p>## Release Process Note
The advisory pre-sets `patched_versions` to the planned next release (`2026.2.22`). After that npm release is published, maintainers can publish this advisory without further version-field edits.</p>
<p>OpenClaw thanks @athuljayaram for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-14849</id>
    <title>cnvd-2026-14849</title>
    <updated>2026-10-03T14:00:24.712494+00:00</updated>
    <content>cnvd-2026-14849</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-14849"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329428</id>
    <title>EUVD-2026-329428</title>
    <updated>2026-10-03T14:00:24.712513+00:00</updated>
    <content>EUVD-2026-329428</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32032</id>
    <title>fkie_cve-2026-32032</title>
    <updated>2026-10-03T14:00:24.712526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHELL path from the host environment. An attacker with local environment access can inject a malicious SHELL variable to execute arbitrary commands with the privileges of the OpenClaw process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f8mp-vj46-cq8v</id>
    <title>GHSA-f8mp-vj46-cq8v — OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment</title>
    <updated>2026-10-03T14:00:24.712547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>The shell environment fallback path could invoke an attacker-controlled shell when `SHELL` was inherited from an untrusted host environment. In affected builds, shell-env loading used `$SHELL -l -c 'env -0'` without validating that `SHELL` points to a trusted executable.</p>
<p>In threat-model terms, this requires local environment compromise or untrusted startup environment injection first; it is not a remote pre-auth path. The hardening patch validates `SHELL` as an absolute normalized executable, prefers `/etc/shells`, applies trusted-prefix fallback checks, and falls back safely to `/bin/sh` when validation fails. The dangerous env-var policy now also blocks `SHELL` overrides.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.2.21-2`
- Latest published vulnerable version: `2026.2.21-2`
- Patched versions (planned next release): `&gt;= 2026.2.22`</p>
<p>## Fix Commit(s)
- `25e89cc86338ef475d26be043aa541dfdb95e52a`</p>
<p>## Release Process Note
The advisory pre-sets `patched_versions` to the planned next release (`2026.2.22`). After that npm release is published, maintainers can publish this advisory without further version-field edits.</p>
<p>OpenClaw thanks @athuljayaram for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f8mp-vj46-cq8v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0472</id>
    <title>WID-SEC-W-2026-0472 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:00:24.712577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0472"/>
  </entry>
</feed>
