<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T16:07:04.450890+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41369</id>
    <title>BREW-openclaw-cli-CVE-2026-41369 — OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables</title>
    <updated>2026-10-05T16:07:04.517044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables</p>
<p>## Current Maintainer Triage
- Normalized severity: medium
- Assessment: v2026.3.28 also misses the broader package, registry, compiler, Docker, and TLS env family in the shipped host-env policy, and the unreleased main fix means this is a real medium-severity open issue.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.28`
- Patched versions: `&gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`</p>
<p>## Fix Commit(s)
- `eb8de6715f02949c21c4e895fffc8a6dcb00975c` — 2026-03-31T19:37:43+09:00</p>
<p>OpenClaw thanks @tdjackey for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41369"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-293333</id>
    <title>EUVD-2026-293333</title>
    <updated>2026-10-05T16:07:04.517119+00:00</updated>
    <content>EUVD-2026-293333</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-293333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41369</id>
    <title>fkie_cve-2026-41369</title>
    <updated>2026-10-05T16:07:04.517137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41369"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cg7q-fg22-4g98</id>
    <title>GHSA-cg7q-fg22-4g98 — OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables</title>
    <updated>2026-10-05T16:07:04.517161+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables</p>
<p>## Current Maintainer Triage
- Normalized severity: medium
- Assessment: v2026.3.28 also misses the broader package, registry, compiler, Docker, and TLS env family in the shipped host-env policy, and the unreleased main fix means this is a real medium-severity open issue.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.28`
- Patched versions: `&gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`</p>
<p>## Fix Commit(s)
- `eb8de6715f02949c21c4e895fffc8a6dcb00975c` — 2026-03-31T19:37:43+09:00</p>
<p>OpenClaw thanks @tdjackey for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cg7q-fg22-4g98"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</id>
    <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T16:07:04.517191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948"/>
  </entry>
</feed>
