<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:16:02.680659+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43533</id>
    <title>BREW-openclaw-cli-CVE-2026-43533 — OpenClaw: QQBot media tags could read arbitrary local files through reply text</title>
    <updated>2026-10-05T22:16:02.746661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>QQBot media tags could read arbitrary local files through reply text.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.10`
- Patched versions: `&gt;= 2026.4.10`</p>
<p>## Impact</p>
<p>QQBot outbound media tags in AI reply text could reference host-local paths outside the intended media storage boundary, allowing local file disclosure through outbound media handling.</p>
<p>## Technical Details</p>
<p>The fix enforces the media storage boundary for all outbound QQBot local file paths.</p>
<p>## Fix</p>
<p>The issue was fixed in #63271. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `604777e4414cc3b2ff8861f18f4fb04374c702c6`
- PR: #63271</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @feiyang666 of Tencent zhuque Lab (https://github.com/Tencent/AI-Infra-Guard) for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308673</id>
    <title>EUVD-2026-308673</title>
    <updated>2026-10-05T22:16:02.746733+00:00</updated>
    <content>EUVD-2026-308673</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43533</id>
    <title>fkie_cve-2026-43533</title>
    <updated>2026-10-05T22:16:02.746750+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-66r7-m7xm-v49h</id>
    <title>GHSA-66r7-m7xm-v49h — OpenClaw: QQBot media tags could read arbitrary local files through reply text</title>
    <updated>2026-10-05T22:16:02.746775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>QQBot media tags could read arbitrary local files through reply text.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.10`
- Patched versions: `&gt;= 2026.4.10`</p>
<p>## Impact</p>
<p>QQBot outbound media tags in AI reply text could reference host-local paths outside the intended media storage boundary, allowing local file disclosure through outbound media handling.</p>
<p>## Technical Details</p>
<p>The fix enforces the media storage boundary for all outbound QQBot local file paths.</p>
<p>## Fix</p>
<p>The issue was fixed in #63271. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `604777e4414cc3b2ff8861f18f4fb04374c702c6`
- PR: #63271</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @feiyang666 of Tencent zhuque Lab (https://github.com/Tencent/AI-Infra-Guard) for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-66r7-m7xm-v49h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</id>
    <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-05T22:16:02.746810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161"/>
  </entry>
</feed>
