<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:55:15.930081+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-40045</id>
    <title>BREW-openclaw-cli-CVE-2026-40045 — OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://</title>
    <updated>2026-10-03T01:55:15.933801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Before OpenClaw 2026.4.2, Android accepted non-loopback cleartext `ws://` gateway endpoints and would send stored gateway credentials over that connection. Discovery beacons or setup codes could therefore steer the client onto a cleartext remote endpoint.</p>
<p>## Impact</p>
<p>A user who followed a forged discovery result or scanned a crafted setup code could disclose stored gateway credentials to an attacker-controlled endpoint in plaintext. This was a transport-security bug in the Android gateway client.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.4.1`
- Patched versions: `&gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`</p>
<p>## Fix Commit(s)</p>
<p>- `a941a4fef9bc43b2973c92d0dcff5b8a426210c5` — require TLS for remote Android gateway endpoints</p>
<p>## Release Process Note</p>
<p>The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live.</p>
<p>Thanks @zsxsoft for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-40045"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292197</id>
    <title>EUVD-2026-292197</title>
    <updated>2026-10-03T01:55:15.933916+00:00</updated>
    <content>EUVD-2026-292197</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40045</id>
    <title>fkie_cve-2026-40045</title>
    <updated>2026-10-03T01:55:15.933942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft setup codes to redirect clients to malicious endpoints, disclosing plaintext gateway credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40045"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-83f3-hh45-vfw9</id>
    <title>GHSA-83f3-hh45-vfw9 — OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://</title>
    <updated>2026-10-03T01:55:15.933979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Before OpenClaw 2026.4.2, Android accepted non-loopback cleartext `ws://` gateway endpoints and would send stored gateway credentials over that connection. Discovery beacons or setup codes could therefore steer the client onto a cleartext remote endpoint.</p>
<p>## Impact</p>
<p>A user who followed a forged discovery result or scanned a crafted setup code could disclose stored gateway credentials to an attacker-controlled endpoint in plaintext. This was a transport-security bug in the Android gateway client.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.4.1`
- Patched versions: `&gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`</p>
<p>## Fix Commit(s)</p>
<p>- `a941a4fef9bc43b2973c92d0dcff5b8a426210c5` — require TLS for remote Android gateway endpoints</p>
<p>## Release Process Note</p>
<p>The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live.</p>
<p>Thanks @zsxsoft for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-83f3-hh45-vfw9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1005</id>
    <title>WID-SEC-W-2026-1005 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T01:55:15.934055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1005"/>
  </entry>
</feed>
