<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:45:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06158</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06158</link>
      <description>bdu:2026-06158</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06158</guid>
    </item>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-28480 — OpenClaw Telegram allowlist authorization accepted mutable usernames</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-28480</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Telegram allowlist authorization could match on `@username` (mutable/recyclable) instead of immutable numeric sender IDs.&lt;/p&gt;
&lt;p&gt;## Impact
Operators who treat Telegram allowlists as strict identity controls could unintentionally grant access if a username changes hands (identity rebinding/spoof risk). This can allow an unauthorized sender to interact with the bot in allowlist mode.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- npm `openclaw`: &amp;lt;= 2026.2.13
- npm `clawdbot`: &amp;lt;= 2026.1.24-3&lt;/p&gt;
&lt;p&gt;## Fix
Telegram allowlist authorization now requires numeric Telegram sender IDs only. `@username` allowlist principals are rejected.&lt;/p&gt;
&lt;p&gt;A security audit warning was added to flag legacy configs that still contain non-numeric Telegram allowlist entries.&lt;/p&gt;
&lt;p&gt;`openclaw doctor --fix` now attempts to resolve `@username` allowFrom entries to numeric IDs (best-effort; requires a Telegram bot token).&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- e3b432e481a96b8fd41b91273818e514074e05c3
- 9e147f00b48e63e7be6964e0e2a97f2980854128&lt;/p&gt;
&lt;p&gt;Thanks @vincentkoc for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Telegram allowlist authorization could match on `@username` (mutable/recyclable) instead of immutable numeric sender IDs.&lt;/p&gt;
&lt;p&gt;## Impact
Operators who treat Telegram allowlists as strict identity controls could unintentionally grant access if a username changes hands (identity rebinding/spoof risk). This can allow an unauthorized sender to interact with the bot in allowlist mode.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- npm `openclaw`: &amp;lt;= 2026.2.13
- npm `clawdbot`: &amp;lt;= 2026.1.24-3&lt;/p&gt;
&lt;p&gt;## Fix
Telegram allowlist authorization now requires numeric Telegram sender IDs only. `@username` allowlist principals are rejected.&lt;/p&gt;
&lt;p&gt;A security audit warning was added to flag legacy configs that still contain non-numeric Telegram allowlist entries.&lt;/p&gt;
&lt;p&gt;`openclaw doctor --fix` now attempts to resolve `@username` allowFrom entries to numeric IDs (best-effort; requires a Telegram bot token).&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- e3b432e481a96b8fd41b91273818e514074e05c3
- 9e147f00b48e63e7be6964e0e2a97f2980854128&lt;/p&gt;
&lt;p&gt;Thanks @vincentkoc for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-28480</guid>
    </item>
    <item>
      <title>cnvd-2026-13544</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-13544</link>
      <description>cnvd-2026-13544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-13544</guid>
    </item>
    <item>
      <title>EUVD-2026-275144</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275144</link>
      <description>EUVD-2026-275144</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275144</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28480</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28480</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28480</guid>
    </item>
    <item>
      <title>GHSA-mj5r-hh7j-4gxf — OpenClaw Telegram allowlist authorization accepted mutable usernames</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mj5r-hh7j-4gxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw, npm: clawdbot&lt;/p&gt;
&lt;p&gt;## Summary
Telegram allowlist authorization could match on `@username` (mutable/recyclable) instead of immutable numeric sender IDs.&lt;/p&gt;
&lt;p&gt;## Impact
Operators who treat Telegram allowlists as strict identity controls could unintentionally grant access if a username changes hands (identity rebinding/spoof risk). This can allow an unauthorized sender to interact with the bot in allowlist mode.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- npm `openclaw`: &amp;lt;= 2026.2.13
- npm `clawdbot`: &amp;lt;= 2026.1.24-3&lt;/p&gt;
&lt;p&gt;## Fix
Telegram allowlist authorization now requires numeric Telegram sender IDs only. `@username` allowlist principals are rejected.&lt;/p&gt;
&lt;p&gt;A security audit warning was added to flag legacy configs that still contain non-numeric Telegram allowlist entries.&lt;/p&gt;
&lt;p&gt;`openclaw doctor --fix` now attempts to resolve `@username` allowFrom entries to numeric IDs (best-effort; requires a Telegram bot token).&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- e3b432e481a96b8fd41b91273818e514074e05c3
- 9e147f00b48e63e7be6964e0e2a97f2980854128&lt;/p&gt;
&lt;p&gt;Thanks @vincentkoc for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw, npm: clawdbot&lt;/p&gt;
&lt;p&gt;## Summary
Telegram allowlist authorization could match on `@username` (mutable/recyclable) instead of immutable numeric sender IDs.&lt;/p&gt;
&lt;p&gt;## Impact
Operators who treat Telegram allowlists as strict identity controls could unintentionally grant access if a username changes hands (identity rebinding/spoof risk). This can allow an unauthorized sender to interact with the bot in allowlist mode.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- npm `openclaw`: &amp;lt;= 2026.2.13
- npm `clawdbot`: &amp;lt;= 2026.1.24-3&lt;/p&gt;
&lt;p&gt;## Fix
Telegram allowlist authorization now requires numeric Telegram sender IDs only. `@username` allowlist principals are rejected.&lt;/p&gt;
&lt;p&gt;A security audit warning was added to flag legacy configs that still contain non-numeric Telegram allowlist entries.&lt;/p&gt;
&lt;p&gt;`openclaw doctor --fix` now attempts to resolve `@username` allowFrom entries to numeric IDs (best-effort; requires a Telegram bot token).&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- e3b432e481a96b8fd41b91273818e514074e05c3
- 9e147f00b48e63e7be6964e0e2a97f2980854128&lt;/p&gt;
&lt;p&gt;Thanks @vincentkoc for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mj5r-hh7j-4gxf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0424 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</link>
      <description>&lt;p&gt;Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann diese Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0424</guid>
    </item>
  </channel>
</rss>
