<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:28:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05240</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05240</link>
      <description>bdu:2026-05240</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05240</guid>
    </item>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-27545 — OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27545</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
For `host=node` executions, approval context could be bypassed after approval-time by rebinding a writable parent symlink in `cwd` while preserving the visible `cwd` string.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.25`
- Fixed: `&amp;gt;= 2026.2.26` (planned next npm release)&lt;/p&gt;
&lt;p&gt;## Impact
A command approved for one filesystem location could execute from a different location if a mutable parent symlink changed between approval and execution.&lt;/p&gt;
&lt;p&gt;## Fix
- Added immutable approval-time plan preparation (`system.run.prepare`) and `systemRunPlanV2` canonical fields (`argv`, `cwd`, `agentId`, `sessionKey`).
- Enforced canonical plan values through approval request storage and forwarding-time sanitization.
- Rejected mutable parent-symlink path components during approval-plan building to block symlink rebind bypass.
- Follow-up refactors centralized command catalogs and approval context/error handling to reduce future drift.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `78a7ff2d50fb3bcef351571cb5a0f21430a340c1`
- `d82c042b09727a6148f3ca651b254c4a677aff26`
- `d06632ba45a8482192792c55d5ff0b2e21abb0a7`
- `4e690e09c746408b5e27617a20cb3fdc5190dbda`
- `4b4718c8dfce2e2c48404aa5088af7c013bed60b`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm `openclaw@2026.2.26` is published, publish this advisory directly without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
For `host=node` executions, approval context could be bypassed after approval-time by rebinding a writable parent symlink in `cwd` while preserving the visible `cwd` string.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.25`
- Fixed: `&amp;gt;= 2026.2.26` (planned next npm release)&lt;/p&gt;
&lt;p&gt;## Impact
A command approved for one filesystem location could execute from a different location if a mutable parent symlink changed between approval and execution.&lt;/p&gt;
&lt;p&gt;## Fix
- Added immutable approval-time plan preparation (`system.run.prepare`) and `systemRunPlanV2` canonical fields (`argv`, `cwd`, `agentId`, `sessionKey`).
- Enforced canonical plan values through approval request storage and forwarding-time sanitization.
- Rejected mutable parent-symlink path components during approval-plan building to block symlink rebind bypass.
- Follow-up refactors centralized command catalogs and approval context/error handling to reduce future drift.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `78a7ff2d50fb3bcef351571cb5a0f21430a340c1`
- `d82c042b09727a6148f3ca651b254c4a677aff26`
- `d06632ba45a8482192792c55d5ff0b2e21abb0a7`
- `4e690e09c746408b5e27617a20cb3fdc5190dbda`
- `4b4718c8dfce2e2c48404aa5088af7c013bed60b`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm `openclaw@2026.2.26` is published, publish this advisory directly without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27545</guid>
    </item>
    <item>
      <title>cnvd-2026-16382</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-16382</link>
      <description>cnvd-2026-16382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-16382</guid>
    </item>
    <item>
      <title>EUVD-2026-329378</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329378</link>
      <description>EUVD-2026-329378</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329378</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27545</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27545</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current working directory after approval. An attacker can modify mutable parent symlink path components between approval and execution time to redirect command execution to a different location while preserving the visible working directory string.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current working directory after approval. An attacker can modify mutable parent symlink path components between approval and execution time to redirect command execution to a different location while preserving the visible working directory string.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27545</guid>
    </item>
    <item>
      <title>GHSA-f7ww-2725-qvw2 — OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f7ww-2725-qvw2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
For `host=node` executions, approval context could be bypassed after approval-time by rebinding a writable parent symlink in `cwd` while preserving the visible `cwd` string.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.25`
- Fixed: `&amp;gt;= 2026.2.26` (planned next npm release)&lt;/p&gt;
&lt;p&gt;## Impact
A command approved for one filesystem location could execute from a different location if a mutable parent symlink changed between approval and execution.&lt;/p&gt;
&lt;p&gt;## Fix
- Added immutable approval-time plan preparation (`system.run.prepare`) and `systemRunPlanV2` canonical fields (`argv`, `cwd`, `agentId`, `sessionKey`).
- Enforced canonical plan values through approval request storage and forwarding-time sanitization.
- Rejected mutable parent-symlink path components during approval-plan building to block symlink rebind bypass.
- Follow-up refactors centralized command catalogs and approval context/error handling to reduce future drift.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `78a7ff2d50fb3bcef351571cb5a0f21430a340c1`
- `d82c042b09727a6148f3ca651b254c4a677aff26`
- `d06632ba45a8482192792c55d5ff0b2e21abb0a7`
- `4e690e09c746408b5e27617a20cb3fdc5190dbda`
- `4b4718c8dfce2e2c48404aa5088af7c013bed60b`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm `openclaw@2026.2.26` is published, publish this advisory directly without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
For `host=node` executions, approval context could be bypassed after approval-time by rebinding a writable parent symlink in `cwd` while preserving the visible `cwd` string.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt;= 2026.2.25`
- Fixed: `&amp;gt;= 2026.2.26` (planned next npm release)&lt;/p&gt;
&lt;p&gt;## Impact
A command approved for one filesystem location could execute from a different location if a mutable parent symlink changed between approval and execution.&lt;/p&gt;
&lt;p&gt;## Fix
- Added immutable approval-time plan preparation (`system.run.prepare`) and `systemRunPlanV2` canonical fields (`argv`, `cwd`, `agentId`, `sessionKey`).
- Enforced canonical plan values through approval request storage and forwarding-time sanitization.
- Rejected mutable parent-symlink path components during approval-plan building to block symlink rebind bypass.
- Follow-up refactors centralized command catalogs and approval context/error handling to reduce future drift.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `78a7ff2d50fb3bcef351571cb5a0f21430a340c1`
- `d82c042b09727a6148f3ca651b254c4a677aff26`
- `d06632ba45a8482192792c55d5ff0b2e21abb0a7`
- `4e690e09c746408b5e27617a20cb3fdc5190dbda`
- `4b4718c8dfce2e2c48404aa5088af7c013bed60b`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm `openclaw@2026.2.26` is published, publish this advisory directly without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f7ww-2725-qvw2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0551 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0551</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0551</guid>
    </item>
  </channel>
</rss>
