<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 13:53:48 +0000</lastBuildDate>
    <item>
      <title>cnvd-2026-13290</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-13290</link>
      <description>cnvd-2026-13290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-13290</guid>
    </item>
    <item>
      <title>EUVD-2026-267435</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267435</link>
      <description>EUVD-2026-267435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267435</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25157</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25157</link>
      <description>&lt;p&gt;OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25157</guid>
    </item>
    <item>
      <title>GHSA-q284-4pvr-m585 — OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q284-4pvr-m585</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: clawdbot&lt;/p&gt;
&lt;p&gt;Two related vulnerabilities existed in the macOS application&amp;#39;s SSH remote connection handling (`CommandResolver.swift`):&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `sshNodeCommand` function constructed a shell script without properly escaping the user-supplied project path in an error message. When the `cd` command failed, the unescaped path was interpolated directly into an `echo` statement, allowing arbitrary command execution **on the remote SSH host**.&lt;/p&gt;
&lt;p&gt;The `parseSSHTarget` function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like `-oProxyCommand=...` would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution **on the local machine**.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can influence a user&amp;#39;s remote connection settings (via social engineering or malicious configuration) could achieve arbitrary code execution on either the user&amp;#39;s local machine or their configured remote SSH host, depending on which input vector is exploited.&lt;/p&gt;
&lt;p&gt;**Affected component:** macOS menubar application (Remote/SSH mode only)&lt;/p&gt;
&lt;p&gt;**Not affected:** CLI (`npm install openclaw`), web gateway, iOS/Android apps, or users running in Local mode.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: clawdbot&lt;/p&gt;
&lt;p&gt;Two related vulnerabilities existed in the macOS application&amp;#39;s SSH remote connection handling (`CommandResolver.swift`):&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `sshNodeCommand` function constructed a shell script without properly escaping the user-supplied project path in an error message. When the `cd` command failed, the unescaped path was interpolated directly into an `echo` statement, allowing arbitrary command execution **on the remote SSH host**.&lt;/p&gt;
&lt;p&gt;The `parseSSHTarget` function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like `-oProxyCommand=...` would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution **on the local machine**.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can influence a user&amp;#39;s remote connection settings (via social engineering or malicious configuration) could achieve arbitrary code execution on either the user&amp;#39;s local machine or their configured remote SSH host, depending on which input vector is exploited.&lt;/p&gt;
&lt;p&gt;**Affected component:** macOS menubar application (Remote/SSH mode only)&lt;/p&gt;
&lt;p&gt;**Not affected:** CLI (`npm install openclaw`), web gateway, iOS/Android apps, or users running in Local mode.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q284-4pvr-m585</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0291 — OpenClaw/Clawdbot: Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0291</link>
      <description>&lt;p&gt;Ein lokaler oder entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw Clawdbot ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler oder entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw Clawdbot ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0291</guid>
    </item>
  </channel>
</rss>
