<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T10:27:42.732498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41370</id>
    <title>BREW-openclaw-cli-CVE-2026-41370 — OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read</title>
    <updated>2026-10-05T10:27:42.832891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read</p>
<p>## Current Maintainer Triage
- Normalized severity: medium
- Assessment: v2026.3.28 ACP dispatch still reads attachment paths outside the guarded attachment-cache or root checks, and the root-enforcement fix is not yet shipped.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.28`
- Patched versions: `&gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`</p>
<p>## Fix Commit(s)
- `566fb73d9da2d73c0be0d9b8e5b762e4dcd8e81d` — 2026-03-30T14:04:02+01:00</p>
<p>OpenClaw thanks @north-echo for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307874</id>
    <title>EUVD-2026-307874</title>
    <updated>2026-10-05T10:27:42.832975+00:00</updated>
    <content>EUVD-2026-307874</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41370</id>
    <title>fkie_cve-2026-41370</title>
    <updated>2026-10-05T10:27:42.832998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pmg8-9xxh-v2wv</id>
    <title>GHSA-pmg8-9xxh-v2wv</title>
    <updated>2026-10-05T10:27:42.833035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pmg8-9xxh-v2wv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</id>
    <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T10:27:42.833062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948"/>
  </entry>
</feed>
