<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:43:34 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32037 — OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In OpenClaw MSTeams media download flows, redirect handling could bypass configured `mediaAllowHosts` checks in specific attachment paths. Redirect chains were not consistently constrained to allowlisted targets before accepting fetched content.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21-2` (latest published at triage time)
- Fixed in: `2026.2.22` (planned next release)&lt;/p&gt;
&lt;p&gt;## Impact
Attackers able to supply or influence attachment URLs could force redirect chains to non-allowlisted targets, weakening SSRF boundary controls for MSTeams media ingestion.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `73d93dee64127a26f1acd09d0403b794cdeb4f5c`
- `b34097f62df9d1960cc22600269cd3f3284e2124`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.22`). Once that npm release is published, this advisory can be published without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In OpenClaw MSTeams media download flows, redirect handling could bypass configured `mediaAllowHosts` checks in specific attachment paths. Redirect chains were not consistently constrained to allowlisted targets before accepting fetched content.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21-2` (latest published at triage time)
- Fixed in: `2026.2.22` (planned next release)&lt;/p&gt;
&lt;p&gt;## Impact
Attackers able to supply or influence attachment URLs could force redirect chains to non-allowlisted targets, weakening SSRF boundary controls for MSTeams media ingestion.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `73d93dee64127a26f1acd09d0403b794cdeb4f5c`
- `b34097f62df9d1960cc22600269cd3f3284e2124`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.22`). Once that npm release is published, this advisory can be published without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32037</guid>
    </item>
    <item>
      <title>EUVD-2026-329433</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329433</link>
      <description>EUVD-2026-329433</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329433</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32037</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32037</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32037</guid>
    </item>
    <item>
      <title>GHSA-w76h-8m22-hpgh — OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w76h-8m22-hpgh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In OpenClaw MSTeams media download flows, redirect handling could bypass configured `mediaAllowHosts` checks in specific attachment paths. Redirect chains were not consistently constrained to allowlisted targets before accepting fetched content.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21-2` (latest published at triage time)
- Fixed in: `2026.2.22` (planned next release)&lt;/p&gt;
&lt;p&gt;## Impact
Attackers able to supply or influence attachment URLs could force redirect chains to non-allowlisted targets, weakening SSRF boundary controls for MSTeams media ingestion.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `73d93dee64127a26f1acd09d0403b794cdeb4f5c`
- `b34097f62df9d1960cc22600269cd3f3284e2124`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.22`). Once that npm release is published, this advisory can be published without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In OpenClaw MSTeams media download flows, redirect handling could bypass configured `mediaAllowHosts` checks in specific attachment paths. Redirect chains were not consistently constrained to allowlisted targets before accepting fetched content.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.2.21-2` (latest published at triage time)
- Fixed in: `2026.2.22` (planned next release)&lt;/p&gt;
&lt;p&gt;## Impact
Attackers able to supply or influence attachment URLs could force redirect chains to non-allowlisted targets, weakening SSRF boundary controls for MSTeams media ingestion.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `73d93dee64127a26f1acd09d0403b794cdeb4f5c`
- `b34097f62df9d1960cc22600269cd3f3284e2124`&lt;/p&gt;
&lt;p&gt;## Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.22`). Once that npm release is published, this advisory can be published without further version-field edits.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w76h-8m22-hpgh</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0586 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0586</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0586</guid>
    </item>
  </channel>
</rss>
