<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:27:09.540924+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35661</id>
    <title>BREW-openclaw-cli-CVE-2026-35661 — OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State</title>
    <updated>2026-10-05T15:27:09.546119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>Telegram callback queries from direct messages previously used weaker callback-only authorization and could mutate session state without satisfying normal DM pairing. Commit `269282ac69ab6030d5f30d04822668f607f13065` enforces DM authorization for callbacks.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `269282ac69ab6030d5f30d04822668f607f13065`.</p>
<p>## Fix Commit(s)</p>
<p>- `269282ac69ab6030d5f30d04822668f607f13065`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329538</id>
    <title>EUVD-2026-329538</title>
    <updated>2026-10-05T15:27:09.546175+00:00</updated>
    <content>EUVD-2026-329538</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329538"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35661</id>
    <title>fkie_cve-2026-35661</title>
    <updated>2026-10-05T15:27:09.546191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows attackers to mutate session state without satisfying normal DM pairing requirements. Remote attackers can exploit weaker callback-only authorization in direct messages to bypass DM pairing and modify session state.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j4c9-w69r-cw33</id>
    <title>GHSA-j4c9-w69r-cw33 — OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State</title>
    <updated>2026-10-05T15:27:09.546214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>Telegram callback queries from direct messages previously used weaker callback-only authorization and could mutate session state without satisfying normal DM pairing. Commit `269282ac69ab6030d5f30d04822668f607f13065` enforces DM authorization for callbacks.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `269282ac69ab6030d5f30d04822668f607f13065`.</p>
<p>## Fix Commit(s)</p>
<p>- `269282ac69ab6030d5f30d04822668f607f13065`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j4c9-w69r-cw33"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884</id>
    <title>WID-SEC-W-2026-0884 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T15:27:09.546243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884"/>
  </entry>
</feed>
