<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:06:28 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32024 — OpenClaw's avatar symlink traversal can expose out-of-workspace local files</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32024</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
OpenClaw avatar handling allowed a symlink traversal path that could expose local files outside an agent workspace through gateway avatar surfaces.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21`, plus prereleases `2026.2.21-1` and `2026.2.21-2`
- Latest published version at triage time (2026-02-22): `2026.2.21-2` (affected)
- Planned patched version (pre-set for release workflow): `2026.2.22`&lt;/p&gt;
&lt;p&gt;### Details
In vulnerable builds, local avatar resolution could follow symlinks and return file bytes from outside the configured workspace boundary.&lt;/p&gt;
&lt;p&gt;The issue was hardened in two paths:
1. Gateway avatar metadata resolution now enforces canonical containment, `O_NOFOLLOW`, and fd/file-identity checks.
2. Control UI avatar serving now rejects symlink paths and enforces fd/file-identity and size checks before reads.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d0337504349954237d09e4d957df5cb844d5e77`
- `6970c2c2db3ee069ef0fff0ade5cfbdd0134f9d2`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.22` so after npm release, the remaining action is to publish this advisory.&lt;/p&gt;
&lt;p&gt;### Impact
Confidentiality impact only: local files readable by the OpenClaw process could be disclosed via avatar response surfaces.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
OpenClaw avatar handling allowed a symlink traversal path that could expose local files outside an agent workspace through gateway avatar surfaces.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21`, plus prereleases `2026.2.21-1` and `2026.2.21-2`
- Latest published version at triage time (2026-02-22): `2026.2.21-2` (affected)
- Planned patched version (pre-set for release workflow): `2026.2.22`&lt;/p&gt;
&lt;p&gt;### Details
In vulnerable builds, local avatar resolution could follow symlinks and return file bytes from outside the configured workspace boundary.&lt;/p&gt;
&lt;p&gt;The issue was hardened in two paths:
1. Gateway avatar metadata resolution now enforces canonical containment, `O_NOFOLLOW`, and fd/file-identity checks.
2. Control UI avatar serving now rejects symlink paths and enforces fd/file-identity and size checks before reads.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d0337504349954237d09e4d957df5cb844d5e77`
- `6970c2c2db3ee069ef0fff0ade5cfbdd0134f9d2`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.22` so after npm release, the remaining action is to publish this advisory.&lt;/p&gt;
&lt;p&gt;### Impact
Confidentiality impact only: local files readable by the OpenClaw process could be disclosed via avatar response surfaces.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32024</guid>
    </item>
    <item>
      <title>cnvd-2026-14858</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-14858</link>
      <description>cnvd-2026-14858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-14858</guid>
    </item>
    <item>
      <title>EUVD-2026-329420</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329420</link>
      <description>EUVD-2026-329420</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329420</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32024</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32024</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avatar resources through gateway surfaces to disclose local files accessible to the OpenClaw process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avatar resources through gateway surfaces to disclose local files accessible to the OpenClaw process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32024</guid>
    </item>
    <item>
      <title>GHSA-rx3g-mvc3-qfjf — OpenClaw's avatar symlink traversal can expose out-of-workspace local files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rx3g-mvc3-qfjf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
OpenClaw avatar handling allowed a symlink traversal path that could expose local files outside an agent workspace through gateway avatar surfaces.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21`, plus prereleases `2026.2.21-1` and `2026.2.21-2`
- Latest published version at triage time (2026-02-22): `2026.2.21-2` (affected)
- Planned patched version (pre-set for release workflow): `2026.2.22`&lt;/p&gt;
&lt;p&gt;### Details
In vulnerable builds, local avatar resolution could follow symlinks and return file bytes from outside the configured workspace boundary.&lt;/p&gt;
&lt;p&gt;The issue was hardened in two paths:
1. Gateway avatar metadata resolution now enforces canonical containment, `O_NOFOLLOW`, and fd/file-identity checks.
2. Control UI avatar serving now rejects symlink paths and enforces fd/file-identity and size checks before reads.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d0337504349954237d09e4d957df5cb844d5e77`
- `6970c2c2db3ee069ef0fff0ade5cfbdd0134f9d2`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.22` so after npm release, the remaining action is to publish this advisory.&lt;/p&gt;
&lt;p&gt;### Impact
Confidentiality impact only: local files readable by the OpenClaw process could be disclosed via avatar response surfaces.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
OpenClaw avatar handling allowed a symlink traversal path that could expose local files outside an agent workspace through gateway avatar surfaces.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21`, plus prereleases `2026.2.21-1` and `2026.2.21-2`
- Latest published version at triage time (2026-02-22): `2026.2.21-2` (affected)
- Planned patched version (pre-set for release workflow): `2026.2.22`&lt;/p&gt;
&lt;p&gt;### Details
In vulnerable builds, local avatar resolution could follow symlinks and return file bytes from outside the configured workspace boundary.&lt;/p&gt;
&lt;p&gt;The issue was hardened in two paths:
1. Gateway avatar metadata resolution now enforces canonical containment, `O_NOFOLLOW`, and fd/file-identity checks.
2. Control UI avatar serving now rejects symlink paths and enforces fd/file-identity and size checks before reads.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d0337504349954237d09e4d957df5cb844d5e77`
- `6970c2c2db3ee069ef0fff0ade5cfbdd0134f9d2`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.22` so after npm release, the remaining action is to publish this advisory.&lt;/p&gt;
&lt;p&gt;### Impact
Confidentiality impact only: local files readable by the OpenClaw process could be disclosed via avatar response surfaces.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rx3g-mvc3-qfjf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0472 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0472</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0472</guid>
    </item>
  </channel>
</rss>
