<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:46:58.977758+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41342</id>
    <title>BREW-openclaw-cli-CVE-2026-41342 — OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials</title>
    <updated>2026-10-04T20:46:58.980880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details.</p>
<p>## Impact</p>
<p>A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic.</p>
<p>## Affected Component</p>
<p>`src/commands/onboard-remote.ts`</p>
<p>## Fixed Versions</p>
<p>- Affected: `&lt;= 2026.3.24`
- Patched: `&gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.</p>
<p>## Fix</p>
<p>Fixed by commit `d6affb17d8` (`CLI: confirm discovered remote gateways before saving config`).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292857</id>
    <title>EUVD-2026-292857</title>
    <updated>2026-10-04T20:46:58.980936+00:00</updated>
    <content>EUVD-2026-292857</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41342</id>
    <title>fkie_cve-2026-41342</title>
    <updated>2026-10-04T20:46:58.980953+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persists unauthenticated discovery endpoints without explicit trust confirmation. Attackers can spoof discovery endpoints to redirect onboarding toward malicious gateways and capture gateway credentials or traffic.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3cw3-5vxw-g2h3</id>
    <title>GHSA-3cw3-5vxw-g2h3 — OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials</title>
    <updated>2026-10-04T20:46:58.980976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details.</p>
<p>## Impact</p>
<p>A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic.</p>
<p>## Affected Component</p>
<p>`src/commands/onboard-remote.ts`</p>
<p>## Fixed Versions</p>
<p>- Affected: `&lt;= 2026.3.24`
- Patched: `&gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.</p>
<p>## Fix</p>
<p>Fixed by commit `d6affb17d8` (`CLI: confirm discovered remote gateways before saving config`).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3cw3-5vxw-g2h3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</id>
    <title>WID-SEC-W-2026-0930 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T20:46:58.981005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930"/>
  </entry>
</feed>
