<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:41:12.070088+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43535</id>
    <title>BREW-openclaw-cli-CVE-2026-43535 — OpenClaw: Collect-mode queue batches could reuse the last sender authorization context</title>
    <updated>2026-10-04T20:41:12.074092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Summary</p>
<p>Collect-mode queue batches could reuse the last sender authorization context.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.14`
- Patched versions: `&gt;= 2026.4.14`</p>
<p>## Impact</p>
<p>Collect-mode queued messages from different senders could be drained as one batch using the final sender's authorization context, allowing earlier messages to inherit a more privileged context.</p>
<p>## Technical Details</p>
<p>The fix splits collect-mode batches by sender authorization context before dispatch, preserving each message's own trust state.</p>
<p>## Fix</p>
<p>The issue was fixed in #66024. The first stable tag containing the fix is `v2026.4.14`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `43d4be902755c970b3d15608679761877718da69`
- PR: #66024</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.14 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43535"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308521</id>
    <title>EUVD-2026-308521</title>
    <updated>2026-10-04T20:41:12.074156+00:00</updated>
    <content>EUVD-2026-308521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43535</id>
    <title>fkie_cve-2026-43535</title>
    <updated>2026-10-04T20:41:12.074173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a more privileged sender's context, causing earlier messages to execute with elevated permissions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43535"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jwrq-8g5x-5fhm</id>
    <title>GHSA-jwrq-8g5x-5fhm — OpenClaw: Collect-mode queue batches could reuse the last sender authorization context</title>
    <updated>2026-10-04T20:41:12.074196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Summary</p>
<p>Collect-mode queue batches could reuse the last sender authorization context.</p>
<p>## Affected Packages / Versions</p>
<p>- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&lt; 2026.4.14`
- Patched versions: `&gt;= 2026.4.14`</p>
<p>## Impact</p>
<p>Collect-mode queued messages from different senders could be drained as one batch using the final sender's authorization context, allowing earlier messages to inherit a more privileged context.</p>
<p>## Technical Details</p>
<p>The fix splits collect-mode batches by sender authorization context before dispatch, preserving each message's own trust state.</p>
<p>## Fix</p>
<p>The issue was fixed in #66024. The first stable tag containing the fix is `v2026.4.14`, and `openclaw@2026.4.14` includes the fix.</p>
<p>## Fix Commit(s)</p>
<p>- `43d4be902755c970b3d15608679761877718da69`
- PR: #66024</p>
<p>## Release Process Note</p>
<p>Users should upgrade to `openclaw` 2026.4.14 or newer. The latest npm release, `2026.4.14`, already includes the fix.</p>
<p>## Credits</p>
<p>Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jwrq-8g5x-5fhm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</id>
    <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-04T20:41:12.074231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161"/>
  </entry>
</feed>
