<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:30:50 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-27183 — OpenClaw: system.run wrapper-depth boundary could skip shell approval gating</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s `system.run` dispatch-wrapper handling applied different depth-boundary rules to shell-wrapper approval detection and execution planning.&lt;/p&gt;
&lt;p&gt;With exactly four transparent dispatch wrappers such as repeated `env` invocations before `/bin/sh -c`, the approval classifier could stop treating the command as a shell wrapper at the depth boundary while execution planning still unwrapped through to the shell payload. In `security=allowlist` mode, that mismatch could skip the expected approval-required path for the shell wrapper invocation.&lt;/p&gt;
&lt;p&gt;Latest published npm version: `2026.3.2`&lt;/p&gt;
&lt;p&gt;Fixed on `main` on March 7, 2026 in `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0` by keeping shell-wrapper classification active at the configured dispatch depth boundary and only failing closed beyond that boundary. This aligns approval gating with the execution plan. Legitimate shallow dispatch-wrapper usage continues to work.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0`&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;npm `2026.3.7` was published on March 8, 2026. This advisory is fixed in the released package.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s `system.run` dispatch-wrapper handling applied different depth-boundary rules to shell-wrapper approval detection and execution planning.&lt;/p&gt;
&lt;p&gt;With exactly four transparent dispatch wrappers such as repeated `env` invocations before `/bin/sh -c`, the approval classifier could stop treating the command as a shell wrapper at the depth boundary while execution planning still unwrapped through to the shell payload. In `security=allowlist` mode, that mismatch could skip the expected approval-required path for the shell wrapper invocation.&lt;/p&gt;
&lt;p&gt;Latest published npm version: `2026.3.2`&lt;/p&gt;
&lt;p&gt;Fixed on `main` on March 7, 2026 in `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0` by keeping shell-wrapper classification active at the configured dispatch depth boundary and only failing closed beyond that boundary. This aligns approval gating with the execution plan. Legitimate shallow dispatch-wrapper usage continues to work.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0`&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;npm `2026.3.7` was published on March 8, 2026. This advisory is fixed in the released package.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27183</guid>
    </item>
    <item>
      <title>cnvd-2026-16391</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-16391</link>
      <description>cnvd-2026-16391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-16391</guid>
    </item>
    <item>
      <title>EUVD-2026-336671</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336671</link>
      <description>EUVD-2026-336671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336671</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27183</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27183</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attackers to skip shell wrapper approval requirements. The approval classifier and execution planner apply different depth-boundary rules, permitting exactly four transparent dispatch wrappers like repeated env invocations before /bin/sh -c to bypass security=allowlist approval gating by misaligning classification with execution planning.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attackers to skip shell wrapper approval requirements. The approval classifier and execution planner apply different depth-boundary rules, permitting exactly four transparent dispatch wrappers like repeated env invocations before /bin/sh -c to bypass security=allowlist approval gating by misaligning classification with execution planning.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27183</guid>
    </item>
    <item>
      <title>GHSA-r6qf-8968-wj9q — OpenClaw: system.run wrapper-depth boundary could skip shell approval gating</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r6qf-8968-wj9q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s `system.run` dispatch-wrapper handling applied different depth-boundary rules to shell-wrapper approval detection and execution planning.&lt;/p&gt;
&lt;p&gt;With exactly four transparent dispatch wrappers such as repeated `env` invocations before `/bin/sh -c`, the approval classifier could stop treating the command as a shell wrapper at the depth boundary while execution planning still unwrapped through to the shell payload. In `security=allowlist` mode, that mismatch could skip the expected approval-required path for the shell wrapper invocation.&lt;/p&gt;
&lt;p&gt;Latest published npm version: `2026.3.2`&lt;/p&gt;
&lt;p&gt;Fixed on `main` on March 7, 2026 in `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0` by keeping shell-wrapper classification active at the configured dispatch depth boundary and only failing closed beyond that boundary. This aligns approval gating with the execution plan. Legitimate shallow dispatch-wrapper usage continues to work.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0`&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;npm `2026.3.7` was published on March 8, 2026. This advisory is fixed in the released package.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s `system.run` dispatch-wrapper handling applied different depth-boundary rules to shell-wrapper approval detection and execution planning.&lt;/p&gt;
&lt;p&gt;With exactly four transparent dispatch wrappers such as repeated `env` invocations before `/bin/sh -c`, the approval classifier could stop treating the command as a shell wrapper at the depth boundary while execution planning still unwrapped through to the shell payload. In `security=allowlist` mode, that mismatch could skip the expected approval-required path for the shell wrapper invocation.&lt;/p&gt;
&lt;p&gt;Latest published npm version: `2026.3.2`&lt;/p&gt;
&lt;p&gt;Fixed on `main` on March 7, 2026 in `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0` by keeping shell-wrapper classification active at the configured dispatch depth boundary and only failing closed beyond that boundary. This aligns approval gating with the execution plan. Legitimate shallow dispatch-wrapper usage continues to work.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0`&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;npm `2026.3.7` was published on March 8, 2026. This advisory is fixed in the released package.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r6qf-8968-wj9q</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0639 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0639</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0639</guid>
    </item>
  </channel>
</rss>
