<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:25:59.576529+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-32971</id>
    <title>CVE-2026-32971 — OpenClaw &lt; 2026.3.11 - Node-Host Approval UI Mismatch Allows Execution of Unintended Commands</title>
    <updated>2026-10-03T22:25:59.606880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenClaw</p>
<p>OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-32971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rw39-5899-8mxp</id>
    <title>GHSA-rw39-5899-8mxp — OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv</title>
    <updated>2026-10-03T22:25:59.606938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could display only an extracted shell payload such as `jq --version` while execution still ran a different outer wrapper argv such as `./env sh -c 'jq --version'`.</p>
<p>## Impact
This is an approval-integrity bug. An attacker who could place or select a local wrapper binary and induce a wrapper-shaped command could get local code executed after the operator approved misleading command text.</p>
<p>## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&lt;= 2026.3.8`
- Fixed in: `2026.3.11`</p>
<p>## Technical Details
Wrapper resolution normalized executables by basename and extracted inner shell payload text for approval display, while execution still preserved the full wrapper argv. Approval storage and UI therefore showed text that did not match the exact command OpenClaw would execute.</p>
<p>## Fix
OpenClaw now binds approvals to the exact executed argv and keeps extracted shell payload text only as secondary preview data. The fix shipped in `openclaw@2026.3.11`.</p>
<p>## Workarounds
Upgrade to `2026.3.11` or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rw39-5899-8mxp"/>
  </entry>
</feed>
