<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:53:04.070930+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-35670</id>
    <title>CVE-2026-35670 — OpenClaw &lt; 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology Chat</title>
    <updated>2026-10-03T19:53:04.106097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenClaw</p>
<p>OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploiting mutable username matching instead of stable numeric user identifiers. Attackers can manipulate username changes to redirect webhook-triggered replies to different users, bypassing the intended recipient binding recorded in webhook events.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-35670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wv46-v6xc-2qhf</id>
    <title>GHSA-wv46-v6xc-2qhf — OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.</title>
    <updated>2026-10-03T19:53:04.106153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
Synology Chat reply delivery could rebind to a mutable username match instead of the stable numeric user_id recorded by the webhook event.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &lt; 2026.3.22
- Fixed: &gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`</p>
<p>## Fix Commit(s)
- `7ade3553b74ee3f461c4acd216653d5ba411f455`</p>
<p>## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.</p>
<p>## Code-Level Confirmation
- extensions/synology-chat/src/webhook-handler.ts now keeps replies bound to the stable webhook user identifier unless an explicit dangerous opt-in is enabled.
- extensions/synology-chat/src/config-schema.ts contains the explicit dangerous opt-in seam instead of silent username rebinding.</p>
<p>OpenClaw thanks @nexrin for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wv46-v6xc-2qhf"/>
  </entry>
</feed>
