<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T22:14:43.459423+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41389</id>
    <title>BREW-openclaw-cli-CVE-2026-41389 — OpenClaw: Webchat media embedding enforces local-root containment for tool-result files</title>
    <updated>2026-10-04T22:14:43.464209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Webchat tool-result media normalization could pass local and UNC-style file paths into the host-side media embedding path without applying the configured local-root containment policy.</p>
<p>## Impact</p>
<p>A crafted tool-result media reference could cause the host to attempt local file reads or Windows UNC/network path access while preparing webchat media blocks. This could disclose allowed host files or trigger network credential exposure on affected Windows deployments. Severity remains medium because exploitation depends on a tool-result media path reaching the webchat embedding path, but the sink is a host-side file read before the user sees the rendered result.</p>
<p>## Affected versions</p>
<p>- Affected: `&gt;= 2026.4.7, &lt; 2026.4.15`
- Patched: `2026.4.15`</p>
<p>## Fix</p>
<p>OpenClaw `2026.4.15` hardens the webchat media path and the shared media resolver. Remote-host `file://` URLs and Windows network paths are rejected before filesystem access, and audio embedding now enforces configured `localRoots` containment before `stat` or read operations.</p>
<p>Verified in `v2026.4.15`:</p>
<p>- `src/gateway/server-methods/chat-webchat-media.ts` uses safe file-URL parsing, rejects Windows network paths, and calls `assertLocalMediaAllowed` before probing local audio files.
- `src/media/web-media.ts` rejects remote-host `file://` URLs, Windows network paths, and local-root bypasses on the shared media path.
- `src/gateway/server-methods/chat-webchat-media.test.ts` covers both remote-host `file://` rejection a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292138</id>
    <title>EUVD-2026-292138</title>
    <updated>2026-10-04T22:14:43.464284+00:00</updated>
    <content>EUVD-2026-292138</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41389</id>
    <title>fkie_cve-2026-41389</title>
    <updated>2026-10-04T22:14:43.464301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mr34-9552-qr95</id>
    <title>GHSA-mr34-9552-qr95 — OpenClaw: Webchat media embedding enforces local-root containment for tool-result files</title>
    <updated>2026-10-04T22:14:43.464324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Webchat tool-result media normalization could pass local and UNC-style file paths into the host-side media embedding path without applying the configured local-root containment policy.</p>
<p>## Impact</p>
<p>A crafted tool-result media reference could cause the host to attempt local file reads or Windows UNC/network path access while preparing webchat media blocks. This could disclose allowed host files or trigger network credential exposure on affected Windows deployments. Severity remains medium because exploitation depends on a tool-result media path reaching the webchat embedding path, but the sink is a host-side file read before the user sees the rendered result.</p>
<p>## Affected versions</p>
<p>- Affected: `&gt;= 2026.4.7, &lt; 2026.4.15`
- Patched: `2026.4.15`</p>
<p>## Fix</p>
<p>OpenClaw `2026.4.15` hardens the webchat media path and the shared media resolver. Remote-host `file://` URLs and Windows network paths are rejected before filesystem access, and audio embedding now enforces configured `localRoots` containment before `stat` or read operations.</p>
<p>Verified in `v2026.4.15`:</p>
<p>- `src/gateway/server-methods/chat-webchat-media.ts` uses safe file-URL parsing, rejects Windows network paths, and calls `assertLocalMediaAllowed` before probing local audio files.
- `src/media/web-media.ts` rejects remote-host `file://` URLs, Windows network paths, and local-root bypasses on the shared media path.
- `src/gateway/server-methods/chat-webchat-media.test.ts` covers both remote-host `file://` rejection a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mr34-9552-qr95"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</id>
    <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T22:14:43.464362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161"/>
  </entry>
</feed>
