<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:45:35.436899+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-41353</id>
    <title>CVE-2026-41353 — OpenClaw &lt; 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection</title>
    <updated>2026-10-03T17:45:35.469069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenClaw</p>
<p>OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-41353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h5hg-h7rr-gpf3</id>
    <title>GHSA-h5hg-h7rr-gpf3 — OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection</title>
    <updated>2026-10-03T17:45:35.469130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection</p>
<p>## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real released allowProfiles bypass through profile mutation and runtime profile selection, fixed and shipped in v2026.3.22+, so keep open for publish rather than close.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.13-1`
- Patched versions: `&gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`</p>
<p>## Fix Commit(s)
- `eac93507c36ccd0c359fba18fa466ef6448be8a5` — 2026-03-23T00:56:44-07:00</p>
<p>## Release Process Note
- The fix is already present in released version `2026.3.22`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.</p>
<p>Thanks @smaeljaish771 for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h5hg-h7rr-gpf3"/>
  </entry>
</feed>
