<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:29:27.264568+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-35636</id>
    <title>CVE-2026-35636 — OpenClaw 2026.3.11 &lt; 2026.3.25 - Session Isolation Bypass via sessionId Resolution</title>
    <updated>2026-10-03T18:29:27.297839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenClaw</p>
<p>OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical session keys before enforcing visibility checks. Sandboxed child sessions can exploit this to access parent or sibling sessions that should be blocked by explicit sessionKey restrictions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-35636"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q2qc-744p-66r2</id>
    <title>GHSA-q2qc-744p-66r2 — OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility</title>
    <updated>2026-10-03T18:29:27.297915+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>`session_status` sessionId resolution bypasses sandboxed session-tree visibility</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Affected versions: `&gt;= 2026.3.11, &lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`</p>
<p>## Details</p>
<p>`session_status` previously resolved a `sessionId` to a canonical session key after early visibility checks, letting sandboxed children reach parent or sibling sessions that were blocked by explicit `sessionKey`. Commit `d9810811b6c3c9266d7580f00574e5e02f7663de` enforces visibility after `sessionId` resolution so sandboxed callers cannot escape their session tree.</p>
<p>Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `d9810811b6c3c9266d7580f00574e5e02f7663de`.</p>
<p>## Fix Commit(s)</p>
<p>- `d9810811b6c3c9266d7580f00574e5e02f7663de`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q2qc-744p-66r2"/>
  </entry>
</feed>
