<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T10:24:49.196023+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-32846</id>
    <title>CVE-2026-32846 — OpenClaw &lt; 2026.3.28 Media Parsing Path Traversal to Arbitrary File Read</title>
    <updated>2026-10-05T10:24:49.246231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenClaw</p>
<p>OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit incomplete validation and the allowBareFilename bypass to reference files outside the intended application sandbox, resulting in disclosure of sensitive information including system files, environment files, and SSH keys.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-32846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f6pf-4gjx-c94r</id>
    <title>GHSA-f6pf-4gjx-c94r — OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read</title>
    <updated>2026-10-05T10:24:49.246313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
OpenClaw &lt;= 2026.3.24 Media Parsing Path Traversal to Arbitrary File Read</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.24`
- Patched versions: `&gt;= 2026.3.28`
- First stable tag containing the fix: `v2026.3.28`</p>
<p>## Fix Commit(s)
- `4797bbc5b96e2cca5532e43b58915c051746fe37` — 2026-03-25T13:35:16-06:00</p>
<p>## Release Process Note
- The fix is already present in released version `2026.3.28`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f6pf-4gjx-c94r"/>
  </entry>
</feed>
