<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:14:45 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-27646 — OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27646</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
Sandboxed requester sessions could reach host-side ACP session initialization through `/acp spawn`.&lt;/p&gt;
&lt;p&gt;OpenClaw already blocked `sessions_spawn({ runtime: &amp;#34;acp&amp;#34; })` from sandboxed sessions, but the slash-command path initialized ACP directly without applying the same host-runtime guard first.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- npm package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;### Details
ACP sessions run on the host, not inside the OpenClaw sandbox. The direct ACP spawn path in `src/agents/acp-spawn.ts` already denied sandboxed requesters, but `/acp spawn` in `src/auto-reply/reply/commands-acp/lifecycle.ts` called `initializeSession(...)` without first applying the same restriction.&lt;/p&gt;
&lt;p&gt;In affected versions, an already authorized sender in a sandboxed session could use `/acp spawn` to cross from sandboxed chat context into host-side ACP runtime initialization when ACP was enabled and a backend was available.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `61000b8e4ded919ca1a825d4700db4cb3fdc56e3`&lt;/p&gt;
&lt;p&gt;### Fix Details
The fix introduced a shared ACP runtime-policy guard in `src/agents/acp-spawn.ts` and reused it from the `/acp spawn` handler in `src/auto-reply/reply/commands-acp/lifecycle.ts` before any ACP backend initialization. Regression coverage was added in `src/auto-reply/reply/commands-acp.test.ts` to prove sandboxed `/acp spawn` requests are rejected early, while existing ACP spawn behavior for non-sandboxed sessions remains unchanged.&lt;/p&gt;
&lt;p&gt;### Relea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
Sandboxed requester sessions could reach host-side ACP session initialization through `/acp spawn`.&lt;/p&gt;
&lt;p&gt;OpenClaw already blocked `sessions_spawn({ runtime: &amp;#34;acp&amp;#34; })` from sandboxed sessions, but the slash-command path initialized ACP directly without applying the same host-runtime guard first.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- npm package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;### Details
ACP sessions run on the host, not inside the OpenClaw sandbox. The direct ACP spawn path in `src/agents/acp-spawn.ts` already denied sandboxed requesters, but `/acp spawn` in `src/auto-reply/reply/commands-acp/lifecycle.ts` called `initializeSession(...)` without first applying the same restriction.&lt;/p&gt;
&lt;p&gt;In affected versions, an already authorized sender in a sandboxed session could use `/acp spawn` to cross from sandboxed chat context into host-side ACP runtime initialization when ACP was enabled and a backend was available.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `61000b8e4ded919ca1a825d4700db4cb3fdc56e3`&lt;/p&gt;
&lt;p&gt;### Fix Details
The fix introduced a shared ACP runtime-policy guard in `src/agents/acp-spawn.ts` and reused it from the `/acp spawn` handler in `src/auto-reply/reply/commands-acp/lifecycle.ts` before any ACP backend initialization. Regression coverage was added in `src/auto-reply/reply/commands-acp.test.ts` to prove sandboxed `/acp spawn` requests are rejected early, while existing ACP spawn behavior for non-sandboxed sessions remains unchanged.&lt;/p&gt;
&lt;p&gt;### Relea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-27646</guid>
    </item>
    <item>
      <title>cnvd-2026-16393</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-16393</link>
      <description>cnvd-2026-16393</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-16393</guid>
    </item>
    <item>
      <title>EUVD-2026-336677</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336677</link>
      <description>EUVD-2026-336677</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336677</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27646</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27646</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn slash-command to cross from sandboxed chat context into host-side ACP session initialization when ACP is enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn slash-command to cross from sandboxed chat context into host-side ACP session initialization when ACP is enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27646</guid>
    </item>
    <item>
      <title>GHSA-9q36-67vc-rrwg — OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9q36-67vc-rrwg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
Sandboxed requester sessions could reach host-side ACP session initialization through `/acp spawn`.&lt;/p&gt;
&lt;p&gt;OpenClaw already blocked `sessions_spawn({ runtime: &amp;#34;acp&amp;#34; })` from sandboxed sessions, but the slash-command path initialized ACP directly without applying the same host-runtime guard first.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- npm package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;### Details
ACP sessions run on the host, not inside the OpenClaw sandbox. The direct ACP spawn path in `src/agents/acp-spawn.ts` already denied sandboxed requesters, but `/acp spawn` in `src/auto-reply/reply/commands-acp/lifecycle.ts` called `initializeSession(...)` without first applying the same restriction.&lt;/p&gt;
&lt;p&gt;In affected versions, an already authorized sender in a sandboxed session could use `/acp spawn` to cross from sandboxed chat context into host-side ACP runtime initialization when ACP was enabled and a backend was available.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `61000b8e4ded919ca1a825d4700db4cb3fdc56e3`&lt;/p&gt;
&lt;p&gt;### Fix Details
The fix introduced a shared ACP runtime-policy guard in `src/agents/acp-spawn.ts` and reused it from the `/acp spawn` handler in `src/auto-reply/reply/commands-acp/lifecycle.ts` before any ACP backend initialization. Regression coverage was added in `src/auto-reply/reply/commands-acp.test.ts` to prove sandboxed `/acp spawn` requests are rejected early, while existing ACP spawn behavior for non-sandboxed sessions remains unchanged.&lt;/p&gt;
&lt;p&gt;### Relea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
Sandboxed requester sessions could reach host-side ACP session initialization through `/acp spawn`.&lt;/p&gt;
&lt;p&gt;OpenClaw already blocked `sessions_spawn({ runtime: &amp;#34;acp&amp;#34; })` from sandboxed sessions, but the slash-command path initialized ACP directly without applying the same host-runtime guard first.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- npm package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.2`
- Patched version: `&amp;gt;= 2026.3.7`&lt;/p&gt;
&lt;p&gt;### Details
ACP sessions run on the host, not inside the OpenClaw sandbox. The direct ACP spawn path in `src/agents/acp-spawn.ts` already denied sandboxed requesters, but `/acp spawn` in `src/auto-reply/reply/commands-acp/lifecycle.ts` called `initializeSession(...)` without first applying the same restriction.&lt;/p&gt;
&lt;p&gt;In affected versions, an already authorized sender in a sandboxed session could use `/acp spawn` to cross from sandboxed chat context into host-side ACP runtime initialization when ACP was enabled and a backend was available.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `61000b8e4ded919ca1a825d4700db4cb3fdc56e3`&lt;/p&gt;
&lt;p&gt;### Fix Details
The fix introduced a shared ACP runtime-policy guard in `src/agents/acp-spawn.ts` and reused it from the `/acp spawn` handler in `src/auto-reply/reply/commands-acp/lifecycle.ts` before any ACP backend initialization. Regression coverage was added in `src/auto-reply/reply/commands-acp.test.ts` to prove sandboxed `/acp spawn` requests are rejected early, while existing ACP spawn behavior for non-sandboxed sessions remains unchanged.&lt;/p&gt;
&lt;p&gt;### Relea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9q36-67vc-rrwg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0639 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0639</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0639</guid>
    </item>
  </channel>
</rss>
