<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:36:15 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32041 — OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32041</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
When browser control started without explicit auth credentials, OpenClaw attempted to bootstrap auth automatically. In affected versions, if that bootstrap step threw an error, startup could continue and expose browser-control routes without authentication.&lt;/p&gt;
&lt;p&gt;### Impact
On affected deployments, a local process (or a loopback-reachable SSRF path) could access browser-control routes, including evaluate-capable actions, without auth.&lt;/p&gt;
&lt;p&gt;### Fix
Startup now fails closed: if bootstrap auth fails and no explicit token/password is configured, browser-control startup aborts.&lt;/p&gt;
&lt;p&gt;### Affected and Patched Versions
- Affected: `&amp;lt;= 2026.2.26`
- Patched: `2026.3.1`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
When browser control started without explicit auth credentials, OpenClaw attempted to bootstrap auth automatically. In affected versions, if that bootstrap step threw an error, startup could continue and expose browser-control routes without authentication.&lt;/p&gt;
&lt;p&gt;### Impact
On affected deployments, a local process (or a loopback-reachable SSRF path) could access browser-control routes, including evaluate-capable actions, without auth.&lt;/p&gt;
&lt;p&gt;### Fix
Startup now fails closed: if bootstrap auth fails and no explicit token/password is configured, browser-control startup aborts.&lt;/p&gt;
&lt;p&gt;### Affected and Patched Versions
- Affected: `&amp;lt;= 2026.2.26`
- Patched: `2026.3.1`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32041</guid>
    </item>
    <item>
      <title>cnvd-2026-14842</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-14842</link>
      <description>cnvd-2026-14842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-14842</guid>
    </item>
    <item>
      <title>EUVD-2026-329437</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329437</link>
      <description>EUVD-2026-329437</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329437</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32041</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32041</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32041</guid>
    </item>
    <item>
      <title>GHSA-vpj2-69hf-rppw — OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vpj2-69hf-rppw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
When browser control started without explicit auth credentials, OpenClaw attempted to bootstrap auth automatically. In affected versions, if that bootstrap step threw an error, startup could continue and expose browser-control routes without authentication.&lt;/p&gt;
&lt;p&gt;### Impact
On affected deployments, a local process (or a loopback-reachable SSRF path) could access browser-control routes, including evaluate-capable actions, without auth.&lt;/p&gt;
&lt;p&gt;### Fix
Startup now fails closed: if bootstrap auth fails and no explicit token/password is configured, browser-control startup aborts.&lt;/p&gt;
&lt;p&gt;### Affected and Patched Versions
- Affected: `&amp;lt;= 2026.2.26`
- Patched: `2026.3.1`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
When browser control started without explicit auth credentials, OpenClaw attempted to bootstrap auth automatically. In affected versions, if that bootstrap step threw an error, startup could continue and expose browser-control routes without authentication.&lt;/p&gt;
&lt;p&gt;### Impact
On affected deployments, a local process (or a loopback-reachable SSRF path) could access browser-control routes, including evaluate-capable actions, without auth.&lt;/p&gt;
&lt;p&gt;### Fix
Startup now fails closed: if bootstrap auth fails and no explicit token/password is configured, browser-control startup aborts.&lt;/p&gt;
&lt;p&gt;### Affected and Patched Versions
- Affected: `&amp;lt;= 2026.2.26`
- Patched: `2026.3.1`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vpj2-69hf-rppw</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0557 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0557</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Berechtigungen zu erlangen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Berechtigungen zu erlangen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0557</guid>
    </item>
  </channel>
</rss>
