<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:41:02.992406+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53812</id>
    <title>BREW-openclaw-cli-CVE-2026-53812 — OpenClaw's browser act interactions could bypass private-network navigation checks</title>
    <updated>2026-10-04T06:41:03.056644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary</p>
<p>OpenClaw's browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.</p>
<p>This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.</p>
<p>### Affected configurations</p>
<p>This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.</p>
<p>### Impact</p>
<p>If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.</p>
<p>The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.</p>
<p>### Patched Versions</p>
<p>The first stable patched version is `2026.5.18`.</p>
<p>### Mitigations</p>
<p>Upgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329564</id>
    <title>EUVD-2026-329564</title>
    <updated>2026-10-04T06:41:03.056715+00:00</updated>
    <content>EUVD-2026-329564</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53812</id>
    <title>fkie_cve-2026-53812</title>
    <updated>2026-10-04T06:41:03.056732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to private-network targets via action-triggered redirects and subsequently read restricted page content using browser evaluation capabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2hfg-4fh4-qp7f</id>
    <title>GHSA-2hfg-4fh4-qp7f — OpenClaw's browser act interactions could bypass private-network navigation checks</title>
    <updated>2026-10-04T06:41:03.056756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>### Summary</p>
<p>OpenClaw's browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.</p>
<p>This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.</p>
<p>### Affected configurations</p>
<p>This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.</p>
<p>### Impact</p>
<p>If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.</p>
<p>The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.</p>
<p>### Patched Versions</p>
<p>The first stable patched version is `2026.5.18`.</p>
<p>### Mitigations</p>
<p>Upgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2hfg-4fh4-qp7f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</id>
    <title>WID-SEC-W-2026-1738 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:41:03.056791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738"/>
  </entry>
</feed>
