<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T03:33:54.773571+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-27485</id>
    <title>CVE-2026-27485 — OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection</title>
    <updated>2026-10-07T03:33:54.775318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openclaw</p>
<p>OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlinks while building .skill archives. If an author runs this script on a crafted local skill directory containing symlinks to files outside the skill root, the resulting archive can include unintended file contents. If exploited, this vulnerability can lead to potential unintentional disclosure of local files from the packaging machine into a generated .skill artifact, but requires local execution of the packaging script on attacker-controlled skill contents. This issue has been fixed in version 2026.2.18.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-27485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r6h2-5gqq-v5v6</id>
    <title>GHSA-r6h2-5gqq-v5v6 — OpenClaw: Reject symlinks in local skill packaging script</title>
    <updated>2026-10-07T03:33:54.775382+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Vulnerability</p>
<p>`skills/skill-creator/scripts/package_skill.py` (a local helper script used when authors package skills) previously followed symlinks while building `.skill` archives.</p>
<p>If an author runs this script on a crafted local skill directory containing symlinks to files outside the skill root, the resulting archive can include unintended file contents.</p>
<p>## Severity and Exposure</p>
<p>- **Severity: Low**
- **Execution context:** local/manual workflow only (skill author packaging step)
- **No remote trigger:** this is not reachable via normal OpenClaw gateway/chat runtime paths
- **No extraction Zip Slip in this finding:** this issue is limited to packaging-time symlink following</p>
<p>## Impact</p>
<p>- Potential unintentional disclosure of local files from the packaging machine into a generated `.skill` artifact.
- Requires local execution of the packaging script on attacker-controlled skill contents.</p>
<p>## Affected Components</p>
<p>- `skills/skill-creator/scripts/package_skill.py`</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw` (npm)
- Latest published version during triage: `2026.2.17`
- Vulnerable version range: `&lt;= 2026.2.17`
- Planned patched version (next release): `2026.2.18`</p>
<p>## Remediation</p>
<p>- Reject symlinks during skill packaging.
- Add regression tests for symlink file and symlink directory cases.
- Update packaging guidance to document the symlink restriction.</p>
<p>## Fix Commit(s)</p>
<p>- `c275932aa4230fb7a8212fe1b9d2a18424874b3f`
- `ee1d6427b544ccadd73e02b1630ea5c29ba9a9f0`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r6h2-5gqq-v5v6"/>
  </entry>
</feed>
