<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:30:21.327340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35617</id>
    <title>BREW-openclaw-cli-CVE-2026-35617 — OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName</title>
    <updated>2026-10-02T15:30:21.391783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>Google Chat group authorization previously relied on mutable space display names, which allowed policy rebinding when names changed or collided. Commit `11ea1f67863d88b6cbcb229dd368a45e07094bff` requires stable group IDs for access decisions.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `11ea1f67863d88b6cbcb229dd368a45e07094bff`.</p>
<p>## Fix Commit(s)</p>
<p>- `11ea1f67863d88b6cbcb229dd368a45e07094bff`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-21182</id>
    <title>cnvd-2026-21182</title>
    <updated>2026-10-02T15:30:21.391850+00:00</updated>
    <content>cnvd-2026-21182</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-21182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329495</id>
    <title>EUVD-2026-329495</title>
    <updated>2026-10-02T15:30:21.391868+00:00</updated>
    <content>EUVD-2026-329495</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35617</id>
    <title>fkie_cve-2026-35617</title>
    <updated>2026-10-02T15:30:21.391880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unauthorized access to protected resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-52q4-3xjc-6778</id>
    <title>GHSA-52q4-3xjc-6778 — OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName</title>
    <updated>2026-10-02T15:30:21.391903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>Google Chat group authorization previously relied on mutable space display names, which allowed policy rebinding when names changed or collided. Commit `11ea1f67863d88b6cbcb229dd368a45e07094bff` requires stable group IDs for access decisions.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `11ea1f67863d88b6cbcb229dd368a45e07094bff`.</p>
<p>## Fix Commit(s)</p>
<p>- `11ea1f67863d88b6cbcb229dd368a45e07094bff`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-52q4-3xjc-6778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884</id>
    <title>WID-SEC-W-2026-0884 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:30:21.391932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884"/>
  </entry>
</feed>
