<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T09:52:46.474809+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43573</id>
    <title>BREW-openclaw-cli-CVE-2026-43573 — OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement</title>
    <updated>2026-10-05T09:52:46.478045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Existing-session browser interaction routes bypassed SSRF policy enforcement.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.10`
- Patched versions: `&gt;= 2026.4.10`</p>
<p>## Impact</p>
<p>Existing-session browser interaction routes could continue interacting with or navigating targets without applying the same SSRF navigation guard used by guarded browser routes.</p>
<p>## Technical Details</p>
<p>The fix guards existing-session navigation and interaction routes with browser navigation policy checks.</p>
<p>## Fix</p>
<p>The issue was fixed in #64370. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `daeb74920d5ad986cb600625180037e23221e93a`
- PR: #64370</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308558</id>
    <title>EUVD-2026-308558</title>
    <updated>2026-10-05T09:52:46.478110+00:00</updated>
    <content>EUVD-2026-308558</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308558"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43573</id>
    <title>fkie_cve-2026-43573</title>
    <updated>2026-10-05T09:52:46.478126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-527m-976r-jf79</id>
    <title>GHSA-527m-976r-jf79 — OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement</title>
    <updated>2026-10-05T09:52:46.478149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Existing-session browser interaction routes bypassed SSRF policy enforcement.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.10`
- Patched versions: `&gt;= 2026.4.10`</p>
<p>## Impact</p>
<p>Existing-session browser interaction routes could continue interacting with or navigating targets without applying the same SSRF navigation guard used by guarded browser routes.</p>
<p>## Technical Details</p>
<p>The fix guards existing-session navigation and interaction routes with browser navigation policy checks.</p>
<p>## Fix</p>
<p>The issue was fixed in #64370. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `daeb74920d5ad986cb600625180037e23221e93a`
- PR: #64370</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-527m-976r-jf79"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</id>
    <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T09:52:46.478183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161"/>
  </entry>
</feed>
