<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:03:03 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32044 — OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32044</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
The `tar.bz2` installer path in `src/agents/skills-install-download.ts` used shell tar preflight/extract logic that did not share the same hardening guarantees as the centralized archive extractor.&lt;/p&gt;
&lt;p&gt;This allowed crafted `.tar.bz2` archives to bypass special-entry blocking and extracted-size guardrails enforced on other archive paths, causing local availability impact during skill install.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published at triage time: `2026.3.1`
- Affected range: `&amp;lt;= 2026.3.1`
- Patched in: `2026.3.2` (released)&lt;/p&gt;
&lt;p&gt;### Impact
Local DoS / availability impact when processing untrusted `.tar.bz2` skill archives.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `0dbb92dd2bcf9a32379d11c0f11ed016669dae3e`&lt;/p&gt;
&lt;p&gt;### Related advisories
- Canonical overlap (closed): GHSA-3pj7-x8jr-jvj8
- Duplicate variant (closed): GHSA-rgr7-g85h-6v82&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
The `tar.bz2` installer path in `src/agents/skills-install-download.ts` used shell tar preflight/extract logic that did not share the same hardening guarantees as the centralized archive extractor.&lt;/p&gt;
&lt;p&gt;This allowed crafted `.tar.bz2` archives to bypass special-entry blocking and extracted-size guardrails enforced on other archive paths, causing local availability impact during skill install.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published at triage time: `2026.3.1`
- Affected range: `&amp;lt;= 2026.3.1`
- Patched in: `2026.3.2` (released)&lt;/p&gt;
&lt;p&gt;### Impact
Local DoS / availability impact when processing untrusted `.tar.bz2` skill archives.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `0dbb92dd2bcf9a32379d11c0f11ed016669dae3e`&lt;/p&gt;
&lt;p&gt;### Related advisories
- Canonical overlap (closed): GHSA-3pj7-x8jr-jvj8
- Duplicate variant (closed): GHSA-rgr7-g85h-6v82&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32044</guid>
    </item>
    <item>
      <title>cnvd-2026-16390</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-16390</link>
      <description>cnvd-2026-16390</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-16390</guid>
    </item>
    <item>
      <title>EUVD-2026-329440</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329440</link>
      <description>EUVD-2026-329440</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329440</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32044</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32044</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32044</guid>
    </item>
    <item>
      <title>GHSA-r44j-6vwc-m7hx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r44j-6vwc-m7hx</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r44j-6vwc-m7hx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0573 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0573</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0573</guid>
    </item>
  </channel>
</rss>
