<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:22:05.692377+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41383</id>
    <title>BREW-openclaw-cli-CVE-2026-41383 — OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped</title>
    <updated>2026-10-03T10:22:05.696106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Before OpenClaw 2026.4.2, the OpenShell mirror backend accepted arbitrary absolute `remoteWorkspaceDir` and `remoteAgentWorkspaceDir` values. In mirror mode, those paths were then used as the target of remote cleanup and overwrite operations.</p>
<p>## Impact</p>
<p>If an attacker could influence those OpenShell config values, mirror sync could delete the contents of an unintended remote directory and replace them with uploaded workspace data. This was a destructive remote-path bug in the mirror-sync path.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.4.1`
- Patched versions: `&gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`</p>
<p>## Fix Commit(s)</p>
<p>- `b21c9840c2e38f4bb338d031511b479d5f07ca25` — constrain OpenShell mirror sync roots</p>
<p>## Release Process Note</p>
<p>The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live.</p>
<p>Thanks @jufeng123768 for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307982</id>
    <title>EUVD-2026-307982</title>
    <updated>2026-10-03T10:22:05.696180+00:00</updated>
    <content>EUVD-2026-307982</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307982"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41383</id>
    <title>fkie_cve-2026-41383</title>
    <updated>2026-10-03T10:22:05.696197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers can manipulate these OpenShell config paths to cause mirror sync operations to delete unintended remote directory contents and replace them with uploaded workspace data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m34q-h93w-vg5x</id>
    <title>GHSA-m34q-h93w-vg5x — OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped</title>
    <updated>2026-10-03T10:22:05.696221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Before OpenClaw 2026.4.2, the OpenShell mirror backend accepted arbitrary absolute `remoteWorkspaceDir` and `remoteAgentWorkspaceDir` values. In mirror mode, those paths were then used as the target of remote cleanup and overwrite operations.</p>
<p>## Impact</p>
<p>If an attacker could influence those OpenShell config values, mirror sync could delete the contents of an unintended remote directory and replace them with uploaded workspace data. This was a destructive remote-path bug in the mirror-sync path.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.4.1`
- Patched versions: `&gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`</p>
<p>## Fix Commit(s)</p>
<p>- `b21c9840c2e38f4bb338d031511b479d5f07ca25` — constrain OpenShell mirror sync roots</p>
<p>## Release Process Note</p>
<p>The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live.</p>
<p>Thanks @jufeng123768 for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m34q-h93w-vg5x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0980</id>
    <title>WID-SEC-W-2026-0980 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:22:05.696255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Daten zu manipulieren, Sicherheitsmechanismen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen..</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0980"/>
  </entry>
</feed>
