<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:36:59 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32055 — OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32055</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
`openclaw` had a workspace boundary bypass in workspace-only path validation: when an in-workspace symlink pointed outside the workspace to a non-existent leaf, the first write could pass validation and create the file outside the workspace.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Vulnerable versions: `&amp;lt;= 2026.2.25`
- Patched versions: `&amp;gt;= 2026.2.26` (pre-set for next planned release)
- Latest published npm version at update time: `2026.2.25`&lt;/p&gt;
&lt;p&gt;### Details
The boundary check path resolved aliases in a way that allowed a non-existent out-of-root symlink target to pass the initial validation window. A first write through the guarded workspace path could therefore escape the workspace boundary.&lt;/p&gt;
&lt;p&gt;The fix hardens canonical boundary resolution so missing-leaf alias paths are evaluated against canonical containment, while preserving valid in-root aliases. This closes the first-write escape condition without regressing valid in-root alias usage.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `46eba86b45e9db05b7b792e914c4fe0de1b40a23`
- `1aef45bc060b28a0af45a67dc66acd36aef763c9`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm release `2026.2.26` is published, this advisory can be published directly.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
`openclaw` had a workspace boundary bypass in workspace-only path validation: when an in-workspace symlink pointed outside the workspace to a non-existent leaf, the first write could pass validation and create the file outside the workspace.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Vulnerable versions: `&amp;lt;= 2026.2.25`
- Patched versions: `&amp;gt;= 2026.2.26` (pre-set for next planned release)
- Latest published npm version at update time: `2026.2.25`&lt;/p&gt;
&lt;p&gt;### Details
The boundary check path resolved aliases in a way that allowed a non-existent out-of-root symlink target to pass the initial validation window. A first write through the guarded workspace path could therefore escape the workspace boundary.&lt;/p&gt;
&lt;p&gt;The fix hardens canonical boundary resolution so missing-leaf alias paths are evaluated against canonical containment, while preserving valid in-root aliases. This closes the first-write escape condition without regressing valid in-root alias usage.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `46eba86b45e9db05b7b792e914c4fe0de1b40a23`
- `1aef45bc060b28a0af45a67dc66acd36aef763c9`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm release `2026.2.26` is published, this advisory can be published directly.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32055</guid>
    </item>
    <item>
      <title>EUVD-2026-329450</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329450</link>
      <description>EUVD-2026-329450</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329450</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32055</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32055</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targets. The vulnerability exists because the boundary check improperly resolves aliases, permitting the first write operation to escape the workspace boundary and create files in arbitrary locations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targets. The vulnerability exists because the boundary check improperly resolves aliases, permitting the first write operation to escape the workspace boundary and create files in arbitrary locations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32055</guid>
    </item>
    <item>
      <title>GHSA-mgrq-9f93-wpp5 — OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mgrq-9f93-wpp5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
`openclaw` had a workspace boundary bypass in workspace-only path validation: when an in-workspace symlink pointed outside the workspace to a non-existent leaf, the first write could pass validation and create the file outside the workspace.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Vulnerable versions: `&amp;lt;= 2026.2.25`
- Patched versions: `&amp;gt;= 2026.2.26` (pre-set for next planned release)
- Latest published npm version at update time: `2026.2.25`&lt;/p&gt;
&lt;p&gt;### Details
The boundary check path resolved aliases in a way that allowed a non-existent out-of-root symlink target to pass the initial validation window. A first write through the guarded workspace path could therefore escape the workspace boundary.&lt;/p&gt;
&lt;p&gt;The fix hardens canonical boundary resolution so missing-leaf alias paths are evaluated against canonical containment, while preserving valid in-root aliases. This closes the first-write escape condition without regressing valid in-root alias usage.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `46eba86b45e9db05b7b792e914c4fe0de1b40a23`
- `1aef45bc060b28a0af45a67dc66acd36aef763c9`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm release `2026.2.26` is published, this advisory can be published directly.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
`openclaw` had a workspace boundary bypass in workspace-only path validation: when an in-workspace symlink pointed outside the workspace to a non-existent leaf, the first write could pass validation and create the file outside the workspace.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Vulnerable versions: `&amp;lt;= 2026.2.25`
- Patched versions: `&amp;gt;= 2026.2.26` (pre-set for next planned release)
- Latest published npm version at update time: `2026.2.25`&lt;/p&gt;
&lt;p&gt;### Details
The boundary check path resolved aliases in a way that allowed a non-existent out-of-root symlink target to pass the initial validation window. A first write through the guarded workspace path could therefore escape the workspace boundary.&lt;/p&gt;
&lt;p&gt;The fix hardens canonical boundary resolution so missing-leaf alias paths are evaluated against canonical containment, while preserving valid in-root aliases. This closes the first-write escape condition without regressing valid in-root alias usage.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `46eba86b45e9db05b7b792e914c4fe0de1b40a23`
- `1aef45bc060b28a0af45a67dc66acd36aef763c9`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to the planned next release (`2026.2.26`). Once npm release `2026.2.26` is published, this advisory can be published directly.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mgrq-9f93-wpp5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</guid>
    </item>
  </channel>
</rss>
