<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T01:07:58.972585+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41386</id>
    <title>BREW-openclaw-cli-CVE-2026-41386 — OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing</title>
    <updated>2026-10-05T01:07:59.042855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary
Bootstrap setup codes were not bound to the intended device role and scopes, allowing first-use privilege escalation during pairing.</p>
<p>## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real first-use bootstrap privilege-escalation bug fixed and shipped in v2026.3.22+, so keep open for publication with current severity.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.13-1`
- Patched versions: `&gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`</p>
<p>## Fix Commit(s)
- `a600c72ed7d0045a27f58bf031d2b36ecb0141c9` — 2026-03-22T23:57:15-07:00</p>
<p>OpenClaw thanks @tdjackey for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307809</id>
    <title>EUVD-2026-307809</title>
    <updated>2026-10-05T01:07:59.042927+00:00</updated>
    <content>EUVD-2026-307809</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41386</id>
    <title>fkie_cve-2026-41386</title>
    <updated>2026-10-05T01:07:59.042944+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gg9v-mgcp-v6m7</id>
    <title>GHSA-gg9v-mgcp-v6m7 — OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing</title>
    <updated>2026-10-05T01:07:59.042968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary
Bootstrap setup codes were not bound to the intended device role and scopes, allowing first-use privilege escalation during pairing.</p>
<p>## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real first-use bootstrap privilege-escalation bug fixed and shipped in v2026.3.22+, so keep open for publication with current severity.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&lt;=2026.3.13-1`
- Patched versions: `&gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`</p>
<p>## Fix Commit(s)
- `a600c72ed7d0045a27f58bf031d2b36ecb0141c9` — 2026-03-22T23:57:15-07:00</p>
<p>OpenClaw thanks @tdjackey for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gg9v-mgcp-v6m7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</id>
    <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T01:07:59.042997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948"/>
  </entry>
</feed>
