<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:59:38.989472+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35650</id>
    <title>BREW-openclaw-cli-CVE-2026-35650 — OpenClaw has Inconsistent Host Exec Environment Override Sanitization</title>
    <updated>2026-10-03T11:59:38.998443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Gateway host exec env override handling did not consistently apply the shared host environment policy, so blocked or malformed override keys could slip through inconsistent sanitization paths.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &lt; 2026.3.22
- Fixed: &gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`</p>
<p>## Fix Commit(s)
- `7abfff756d6c68d17e21d1657bbacbaec86de232`</p>
<p>## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.</p>
<p>## Code-Level Confirmation
- src/infra/host-env-security.ts now provides one shared sanitizer and fail-closed diagnostics for blocked or malformed override keys.
- src/agents/bash-tools.exec.ts and src/node-host/invoke-system-run.ts both route env overrides through the shared sanitizer before execution.</p>
<p>OpenClaw thanks @zpbrent for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35650"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329527</id>
    <title>EUVD-2026-329527</title>
    <updated>2026-10-03T11:59:38.998501+00:00</updated>
    <content>EUVD-2026-329527</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35650</id>
    <title>fkie_cve-2026-35650</title>
    <updated>2026-10-03T11:59:38.998517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent sanitization paths. Attackers can supply blocked or malformed override keys that slip through inconsistent validation to execute arbitrary code with unintended environment variables.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35650"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-39pp-xp36-q6mg</id>
    <title>GHSA-39pp-xp36-q6mg — OpenClaw has Inconsistent Host Exec Environment Override Sanitization</title>
    <updated>2026-10-03T11:59:38.998540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
Gateway host exec env override handling did not consistently apply the shared host environment policy, so blocked or malformed override keys could slip through inconsistent sanitization paths.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &lt; 2026.3.22
- Fixed: &gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`</p>
<p>## Fix Commit(s)
- `7abfff756d6c68d17e21d1657bbacbaec86de232`</p>
<p>## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.</p>
<p>## Code-Level Confirmation
- src/infra/host-env-security.ts now provides one shared sanitizer and fail-closed diagnostics for blocked or malformed override keys.
- src/agents/bash-tools.exec.ts and src/node-host/invoke-system-run.ts both route env overrides through the shared sanitizer before execution.</p>
<p>OpenClaw thanks @zpbrent for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-39pp-xp36-q6mg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884</id>
    <title>WID-SEC-W-2026-0884 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:59:38.998569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884"/>
  </entry>
</feed>
