<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:47:15.608498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32924</id>
    <title>BREW-openclaw-cli-CVE-2026-32924 — OpenClaw: Feishu reaction events could bypass group authorization and mention gating</title>
    <updated>2026-10-03T19:47:15.683001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary</p>
<p>A Feishu reaction-originated synthetic event could misclassify a group conversation as `p2p` when the inbound reaction payload omitted `chat_type`. Authorization and mention-gating logic keyed off that incorrect chat type and evaluated the event as a direct message instead of a group message.</p>
<p>### Impact</p>
<p>This could bypass `groupAllowFrom` and `requireMention` protections for reaction-derived events in Feishu group chats.</p>
<p>### Affected versions</p>
<p>`openclaw` `&lt;= 2026.3.11`</p>
<p>### Patch</p>
<p>Fixed in `openclaw` `2026.3.12`. Reaction events now preserve the correct group context before authorization and mention-gate evaluation. Users should update to `2026.3.12` or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-16695</id>
    <title>cnvd-2026-16695</title>
    <updated>2026-10-03T19:47:15.683068+00:00</updated>
    <content>cnvd-2026-16695</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-16695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329473</id>
    <title>EUVD-2026-329473</title>
    <updated>2026-10-03T19:47:15.683087+00:00</updated>
    <content>EUVD-2026-329473</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32924</id>
    <title>fkie_cve-2026-32924</title>
    <updated>2026-10-03T19:47:15.683100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAllowFrom and requireMention protections in group chat reaction-derived events.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-988c-qpg2-7hpv</id>
    <title>GHSA-988c-qpg2-7hpv</title>
    <updated>2026-10-03T19:47:15.683123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAllowFrom and requireMention protections in group chat reaction-derived events.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-988c-qpg2-7hpv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</id>
    <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:47:15.683139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711"/>
  </entry>
</feed>
