<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:33:24.368612+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05248</id>
    <title>bdu:2026-05248</title>
    <updated>2026-10-08T16:33:24.462510+00:00</updated>
    <content>bdu:2026-05248</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27523</id>
    <title>BREW-openclaw-cli-CVE-2026-27523 — OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf pa…</title>
    <updated>2026-10-08T16:33:24.462550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary
In `openclaw` up to and including **2026.2.23** (latest npm release as of **February 24, 2026**), sandbox bind-source validation could be bypassed when a bind source used a symlinked parent plus a non-existent leaf path.</p>
<p>### Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&lt;= 2026.2.23`
- Patched: `&gt;= 2026.2.24` (planned next release)</p>
<p>### Root Cause
`validateBindMounts` previously relied on full-path realpath only when the full source path already existed. For missing-leaf paths, parent symlink traversal was not fully canonicalized before allowed-root and blocked-path checks.</p>
<p>### Security Impact
A source path that looked inside an allowed root could resolve outside that root (including blocked runtime paths) once the missing leaf was created, weakening sandbox bind-source boundary enforcement.</p>
<p>### Fix
The validation path now canonicalizes through the nearest existing ancestor, then always re-checks the canonical path against both:
- allowed source roots
- blocked runtime paths</p>
<p>### Verification
- `pnpm check`
- `pnpm exec vitest run --config vitest.gateway.config.ts`
- `pnpm test:fast`
- Added regression tests for symlink-parent + missing-leaf bypass patterns.</p>
<p>### Fix Commit(s)
- `b5787e4abba0dcc6baf09051099f6773c1679ec1`</p>
<p>### Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.24`) so after npm publish the advisory can be published without further field edits.</p>
<p>OpenClaw thanks @tdjackey for reporting.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-16057</id>
    <title>cnvd-2026-16057</title>
    <updated>2026-10-08T16:33:24.462653+00:00</updated>
    <content>cnvd-2026-16057</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-16057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329376</id>
    <title>EUVD-2026-329376</title>
    <updated>2026-10-08T16:33:24.462676+00:00</updated>
    <content>EUVD-2026-329376</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27523</id>
    <title>fkie_cve-2026-27523</title>
    <updated>2026-10-08T16:33:24.462695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind source paths that appear within allowed roots but resolve outside sandbox boundaries once missing leaf components are created, weakening bind-source isolation enforcement.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m8v2-6wwh-r4gc</id>
    <title>GHSA-m8v2-6wwh-r4gc — OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf pa…</title>
    <updated>2026-10-08T16:33:24.462732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>### Summary
In `openclaw` up to and including **2026.2.23** (latest npm release as of **February 24, 2026**), sandbox bind-source validation could be bypassed when a bind source used a symlinked parent plus a non-existent leaf path.</p>
<p>### Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&lt;= 2026.2.23`
- Patched: `&gt;= 2026.2.24` (planned next release)</p>
<p>### Root Cause
`validateBindMounts` previously relied on full-path realpath only when the full source path already existed. For missing-leaf paths, parent symlink traversal was not fully canonicalized before allowed-root and blocked-path checks.</p>
<p>### Security Impact
A source path that looked inside an allowed root could resolve outside that root (including blocked runtime paths) once the missing leaf was created, weakening sandbox bind-source boundary enforcement.</p>
<p>### Fix
The validation path now canonicalizes through the nearest existing ancestor, then always re-checks the canonical path against both:
- allowed source roots
- blocked runtime paths</p>
<p>### Verification
- `pnpm check`
- `pnpm exec vitest run --config vitest.gateway.config.ts`
- `pnpm test:fast`
- Added regression tests for symlink-parent + missing-leaf bypass patterns.</p>
<p>### Fix Commit(s)
- `b5787e4abba0dcc6baf09051099f6773c1679ec1`</p>
<p>### Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.24`) so after npm publish the advisory can be published without further field edits.</p>
<p>OpenClaw thanks @tdjackey for reporting.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m8v2-6wwh-r4gc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0501</id>
    <title>WID-SEC-W-2026-0501 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-08T16:33:24.462818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen oder andere nicht näher definierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0501"/>
  </entry>
</feed>
