<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:29:23.834861+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32977</id>
    <title>BREW-openclaw-cli-CVE-2026-32977 — OpenClaw: Sandbox `writeFile` commit could race outside the validated path</title>
    <updated>2026-10-02T16:29:23.838516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path.</p>
<p>## Impact
This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace.</p>
<p>## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&lt; 2026.3.11`
- Fixed in: `2026.3.11`</p>
<p>## Technical Details
The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step.</p>
<p>## Fix
OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `openclaw@2026.3.11`.</p>
<p>## Workarounds
Upgrade to `2026.3.11` or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-17185</id>
    <title>cnvd-2026-17185</title>
    <updated>2026-10-02T16:29:23.838572+00:00</updated>
    <content>cnvd-2026-17185</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-17185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329481</id>
    <title>EUVD-2026-329481</title>
    <updated>2026-10-02T16:29:23.838589+00:00</updated>
    <content>EUVD-2026-329481</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32977</id>
    <title>fkie_cve-2026-32977</title>
    <updated>2026-10-02T16:29:23.838601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xvx8-77m6-gwg6</id>
    <title>GHSA-xvx8-77m6-gwg6 — OpenClaw: Sandbox `writeFile` commit could race outside the validated path</title>
    <updated>2026-10-02T16:29:23.838622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path.</p>
<p>## Impact
This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace.</p>
<p>## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&lt; 2026.3.11`
- Fixed in: `2026.3.11`</p>
<p>## Technical Details
The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step.</p>
<p>## Fix
OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `openclaw@2026.3.11`.</p>
<p>## Workarounds
Upgrade to `2026.3.11` or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xvx8-77m6-gwg6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</id>
    <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:29:23.838652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711"/>
  </entry>
</feed>
