<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:42:23.473932+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32920</id>
    <title>BREW-openclaw-cli-CVE-2026-32920 — OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories</title>
    <updated>2026-10-05T13:42:23.536110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary</p>
<p>OpenClaw automatically discovered and loaded plugins from `.openclaw/extensions/` inside the current workspace without an explicit trust or install step. A malicious repository could include a crafted workspace plugin that executed as soon as a user ran OpenClaw from that cloned directory.</p>
<p>### Impact</p>
<p>Opening or running OpenClaw in an untrusted repository could lead to arbitrary code execution under the user's account.</p>
<p>### Affected versions</p>
<p>`openclaw` `&lt;= 2026.3.11`</p>
<p>### Patch</p>
<p>Fixed in `openclaw` `2026.3.12`. Workspace plugin loading now requires explicit trusted state before execution. Users should update to `2026.3.12` or later and avoid running OpenClaw inside untrusted repositories on older releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-19641</id>
    <title>cnvd-2026-19641</title>
    <updated>2026-10-05T13:42:23.536170+00:00</updated>
    <content>cnvd-2026-19641</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-19641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329469</id>
    <title>EUVD-2026-329469</title>
    <updated>2026-10-05T13:42:23.536189+00:00</updated>
    <content>EUVD-2026-329469</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32920</id>
    <title>fkie_cve-2026-32920</title>
    <updated>2026-10-05T13:42:23.536201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-99qw-6mr3-36qr</id>
    <title>GHSA-99qw-6mr3-36qr — OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories</title>
    <updated>2026-10-05T13:42:23.536223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>### Summary</p>
<p>OpenClaw automatically discovered and loaded plugins from `.openclaw/extensions/` inside the current workspace without an explicit trust or install step. A malicious repository could include a crafted workspace plugin that executed as soon as a user ran OpenClaw from that cloned directory.</p>
<p>### Impact</p>
<p>Opening or running OpenClaw in an untrusted repository could lead to arbitrary code execution under the user's account.</p>
<p>### Affected versions</p>
<p>`openclaw` `&lt;= 2026.3.11`</p>
<p>### Patch</p>
<p>Fixed in `openclaw` `2026.3.12`. Workspace plugin loading now requires explicit trusted state before execution. Users should update to `2026.3.12` or later and avoid running OpenClaw inside untrusted repositories on older releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-99qw-6mr3-36qr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</id>
    <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T13:42:23.536252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711"/>
  </entry>
</feed>
