<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:11:53.172641+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43574</id>
    <title>BREW-openclaw-cli-CVE-2026-43574 — OpenClaw: Empty approver lists could grant explicit approval authorization</title>
    <updated>2026-10-03T23:11:53.176144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Empty approver lists could grant explicit approval authorization.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.12`
- Patched versions: `&gt;= 2026.4.12`</p>
<p>## Impact</p>
<p>For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.</p>
<p>## Technical Details</p>
<p>The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.</p>
<p>## Fix</p>
<p>The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @anshumanbh for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308523</id>
    <title>EUVD-2026-308523</title>
    <updated>2026-10-03T23:11:53.176266+00:00</updated>
    <content>EUVD-2026-308523</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43574</id>
    <title>fkie_cve-2026-43574</title>
    <updated>2026-10-03T23:11:53.176295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-49cg-279w-m73x</id>
    <title>GHSA-49cg-279w-m73x — OpenClaw: Empty approver lists could grant explicit approval authorization</title>
    <updated>2026-10-03T23:11:53.176345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Empty approver lists could grant explicit approval authorization.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.12`
- Patched versions: `&gt;= 2026.4.12`</p>
<p>## Impact</p>
<p>For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.</p>
<p>## Technical Details</p>
<p>The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.</p>
<p>## Fix</p>
<p>The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @anshumanbh for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-49cg-279w-m73x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1174</id>
    <title>WID-SEC-W-2026-1174 — OpenClaw: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T23:11:53.176433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in OpenClaw ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1174"/>
  </entry>
</feed>
