<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:22:44.006021+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35654</id>
    <title>BREW-openclaw-cli-CVE-2026-35654 — OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback</title>
    <updated>2026-10-03T11:22:44.072491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>MS Teams Feedback Invoke Bypasses Sender Allowlists and Records Unauthorized Session Feedback</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>Microsoft Teams feedback invokes previously bypassed sender authorization and could record feedback or trigger reflection for unauthorized senders. Commit `c5415a474bb085404c20f8b312e436997977b1ea` applies the same DM and group authorization checks to feedback invokes.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `c5415a474bb085404c20f8b312e436997977b1ea`.</p>
<p>## Fix Commit(s)</p>
<p>- `c5415a474bb085404c20f8b312e436997977b1ea`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329531</id>
    <title>EUVD-2026-329531</title>
    <updated>2026-10-03T11:22:44.072556+00:00</updated>
    <content>EUVD-2026-329531</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35654</id>
    <title>fkie_cve-2026-35654</title>
    <updated>2026-10-03T11:22:44.072573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows unauthorized senders to record session feedback. Attackers can bypass sender allowlist checks via feedback invoke endpoints to trigger unauthorized feedback recording or reflection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rf6h-5gpw-qrgq</id>
    <title>GHSA-rf6h-5gpw-qrgq — OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback</title>
    <updated>2026-10-03T11:22:44.072596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>MS Teams Feedback Invoke Bypasses Sender Allowlists and Records Unauthorized Session Feedback</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>Microsoft Teams feedback invokes previously bypassed sender authorization and could record feedback or trigger reflection for unauthorized senders. Commit `c5415a474bb085404c20f8b312e436997977b1ea` applies the same DM and group authorization checks to feedback invokes.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `c5415a474bb085404c20f8b312e436997977b1ea`.</p>
<p>## Fix Commit(s)</p>
<p>- `c5415a474bb085404c20f8b312e436997977b1ea`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rf6h-5gpw-qrgq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065</id>
    <title>WID-SEC-W-2026-1065 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:22:44.072624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065"/>
  </entry>
</feed>
