<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:59:27.899422+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35651</id>
    <title>BREW-openclaw-cli-CVE-2026-35651 — OpenClaw has ACP CLI approval prompt ANSI escape sequence injection</title>
    <updated>2026-10-03T10:59:27.961535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>ACP CLI approval prompt ANSI escape sequence injection</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&gt;= 2026.2.13, &lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>ACP tool titles could previously carry ANSI control sequences into approval prompts and permission logs, letting untrusted tool metadata spoof terminal output. Commit `464e2c10a5edceb380d815adb6ff56e1a4c50f60` sanitizes tool titles at the source and broadens ANSI stripping to full CSI sequences.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `464e2c10a5edceb380d815adb6ff56e1a4c50f60`.</p>
<p>## Fix Commit(s)</p>
<p>- `464e2c10a5edceb380d815adb6ff56e1a4c50f60`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329528</id>
    <title>EUVD-2026-329528</title>
    <updated>2026-10-03T10:59:27.961598+00:00</updated>
    <content>EUVD-2026-329528</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329528"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35651</id>
    <title>fkie_cve-2026-35651</title>
    <updated>2026-10-03T10:59:27.961614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences into approval prompts and permission logs, enabling attackers to manipulate displayed information through malicious tool titles.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4hmj-39m8-jwc7</id>
    <title>GHSA-4hmj-39m8-jwc7 — OpenClaw has ACP CLI approval prompt ANSI escape sequence injection</title>
    <updated>2026-10-03T10:59:27.961637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>ACP CLI approval prompt ANSI escape sequence injection</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&gt;= 2026.2.13, &lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>ACP tool titles could previously carry ANSI control sequences into approval prompts and permission logs, letting untrusted tool metadata spoof terminal output. Commit `464e2c10a5edceb380d815adb6ff56e1a4c50f60` sanitizes tool titles at the source and broadens ANSI stripping to full CSI sequences.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `464e2c10a5edceb380d815adb6ff56e1a4c50f60`.</p>
<p>## Fix Commit(s)</p>
<p>- `464e2c10a5edceb380d815adb6ff56e1a4c50f60`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4hmj-39m8-jwc7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884</id>
    <title>WID-SEC-W-2026-0884 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:59:27.961666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884"/>
  </entry>
</feed>
