<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:02:51.205401+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35668</id>
    <title>BREW-openclaw-cli-CVE-2026-35668 — OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)</title>
    <updated>2026-10-03T08:02:51.275514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>&gt; Fixed in OpenClaw 2026.3.24, the current shipping release.</p>
<p>### Advisory Details
**Title**: Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)</p>
<p>**Description**:
### Summary
A path traversal vulnerability in the agent sandbox enforcement allows a sandboxed agent to read arbitrary files from other agents' workspaces by using the `mediaUrl` or `fileUrl` parameter key in message tool calls. The `normalizeSandboxMediaParams` function only checks `["media", "path", "filePath"]` keys, while `mediaUrl` and `fileUrl` escape normalization entirely. Combined with `handlePluginAction` dropping `mediaLocalRoots` from the dispatch context, this enables a full sandbox escape where any agent can read files outside its designated sandbox root.</p>
<p>### Details
The vulnerability exists in two files within the messaging pipeline:</p>
<p>**1. Incomplete parameter key coverage in `normalizeSandboxMediaParams`:**</p>
<p>In `src/infra/outbound/message-action-params.ts`, the function iterates over a hardcoded allowlist of parameter keys to validate:</p>
<p>```typescript
// Line 212
const mediaKeys: Array&lt;"media" | "path" | "filePath"&gt; = ["media", "path", "filePath"];
```</p>
<p>The `mediaUrl` and `fileUrl` parameter keys are not included in this array. These keys are actively used by multiple channel extensions (Discord, Telegram, Slack, Matrix, Twitch) for media attachment handling, but they completely bypass the sandbox path validation performed by `resolveSandboxedMediaSource`.</p>
<p>**2…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329545</id>
    <title>EUVD-2026-329545</title>
    <updated>2026-10-03T08:02:51.275617+00:00</updated>
    <content>EUVD-2026-329545</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35668</id>
    <title>fkie_cve-2026-35668</title>
    <updated>2026-10-03T08:02:51.275634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other agents' workspaces via unnormalized mediaUrl or fileUrl parameter keys. Attackers can exploit incomplete parameter validation in normalizeSandboxMediaParams and missing mediaLocalRoots context to access sensitive files including API keys and configuration data outside designated sandbox roots.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hr5v-j9h9-xjhg</id>
    <title>GHSA-hr5v-j9h9-xjhg — OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)</title>
    <updated>2026-10-03T08:02:51.275659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>&gt; Fixed in OpenClaw 2026.3.24, the current shipping release.</p>
<p>### Advisory Details
**Title**: Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)</p>
<p>**Description**:
### Summary
A path traversal vulnerability in the agent sandbox enforcement allows a sandboxed agent to read arbitrary files from other agents' workspaces by using the `mediaUrl` or `fileUrl` parameter key in message tool calls. The `normalizeSandboxMediaParams` function only checks `["media", "path", "filePath"]` keys, while `mediaUrl` and `fileUrl` escape normalization entirely. Combined with `handlePluginAction` dropping `mediaLocalRoots` from the dispatch context, this enables a full sandbox escape where any agent can read files outside its designated sandbox root.</p>
<p>### Details
The vulnerability exists in two files within the messaging pipeline:</p>
<p>**1. Incomplete parameter key coverage in `normalizeSandboxMediaParams`:**</p>
<p>In `src/infra/outbound/message-action-params.ts`, the function iterates over a hardcoded allowlist of parameter keys to validate:</p>
<p>```typescript
// Line 212
const mediaKeys: Array&lt;"media" | "path" | "filePath"&gt; = ["media", "path", "filePath"];
```</p>
<p>The `mediaUrl` and `fileUrl` parameter keys are not included in this array. These keys are actively used by multiple channel extensions (Discord, Telegram, Slack, Matrix, Twitch) for media attachment handling, but they completely bypass the sandbox path validation performed by `resolveSandboxedMediaSource`.</p>
<p>**2…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hr5v-j9h9-xjhg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065</id>
    <title>WID-SEC-W-2026-1065 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:02:51.275723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065"/>
  </entry>
</feed>
