<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:11:48.493043+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35644</id>
    <title>BREW-openclaw-cli-CVE-2026-35644 — OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status</title>
    <updated>2026-10-02T22:11:48.496713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Read-scoped gateway snapshots could expose credentials embedded in channel baseUrl and related endpoint fields.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &lt; 2026.3.22
- Fixed: &gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`</p>
<p>## Fix Commit(s)
- `f0202264d0de7ad345382b9008c5963bcefb01b7`</p>
<p>## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.</p>
<p>## Code-Level Confirmation
- src/channels/account-snapshot-fields.ts now strips URL userinfo from channel status snapshot fields.
- src/config/redact-snapshot.ts now redacts credential-bearing baseUrl and httpUrl fields while preserving safe context.</p>
<p>OpenClaw thanks @zpbrent for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35644"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329521</id>
    <title>EUVD-2026-329521</title>
    <updated>2026-10-02T22:11:48.496778+00:00</updated>
    <content>EUVD-2026-329521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35644</id>
    <title>fkie_cve-2026-35644</title>
    <updated>2026-10-02T22:11:48.496794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via config.get and channels.status endpoints to retrieve sensitive authentication information from URL userinfo components.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35644"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cp2c-jpv3-3r5r</id>
    <title>GHSA-cp2c-jpv3-3r5r</title>
    <updated>2026-10-02T22:11:48.496817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via config.get and channels.status endpoints to retrieve sensitive authentication information from URL userinfo components.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cp2c-jpv3-3r5r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</id>
    <title>WID-SEC-W-2026-0856 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:11:48.496833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856"/>
  </entry>
</feed>
