<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T11:57:18.948774+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32044</id>
    <title>BREW-openclaw-cli-CVE-2026-32044 — OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)</title>
    <updated>2026-10-06T11:57:18.952358+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>### Summary
The `tar.bz2` installer path in `src/agents/skills-install-download.ts` used shell tar preflight/extract logic that did not share the same hardening guarantees as the centralized archive extractor.</p>
<p>This allowed crafted `.tar.bz2` archives to bypass special-entry blocking and extracted-size guardrails enforced on other archive paths, causing local availability impact during skill install.</p>
<p>### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published at triage time: `2026.3.1`
- Affected range: `&lt;= 2026.3.1`
- Patched in: `2026.3.2` (released)</p>
<p>### Impact
Local DoS / availability impact when processing untrusted `.tar.bz2` skill archives.</p>
<p>### Fix Commit(s)
- `0dbb92dd2bcf9a32379d11c0f11ed016669dae3e`</p>
<p>### Related advisories
- Canonical overlap (closed): GHSA-3pj7-x8jr-jvj8
- Duplicate variant (closed): GHSA-rgr7-g85h-6v82</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-16390</id>
    <title>cnvd-2026-16390</title>
    <updated>2026-10-06T11:57:18.952430+00:00</updated>
    <content>cnvd-2026-16390</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-16390"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329440</id>
    <title>EUVD-2026-329440</title>
    <updated>2026-10-06T11:57:18.952448+00:00</updated>
    <content>EUVD-2026-329440</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32044</id>
    <title>fkie_cve-2026-32044</title>
    <updated>2026-10-06T11:57:18.952460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r44j-6vwc-m7hx</id>
    <title>GHSA-r44j-6vwc-m7hx</title>
    <updated>2026-10-06T11:57:18.952481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r44j-6vwc-m7hx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0573</id>
    <title>WID-SEC-W-2026-0573 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-06T11:57:18.952496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0573"/>
  </entry>
</feed>
