<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:15:21 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32971 — OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32971</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could display only an extracted shell payload such as `jq --version` while execution still ran a different outer wrapper argv such as `./env sh -c &amp;#39;jq --version&amp;#39;`.&lt;/p&gt;
&lt;p&gt;## Impact
This is an approval-integrity bug. An attacker who could place or select a local wrapper binary and induce a wrapper-shaped command could get local code executed after the operator approved misleading command text.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
Wrapper resolution normalized executables by basename and extracted inner shell payload text for approval display, while execution still preserved the full wrapper argv. Approval storage and UI therefore showed text that did not match the exact command OpenClaw would execute.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now binds approvals to the exact executed argv and keeps extracted shell payload text only as secondary preview data. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could display only an extracted shell payload such as `jq --version` while execution still ran a different outer wrapper argv such as `./env sh -c &amp;#39;jq --version&amp;#39;`.&lt;/p&gt;
&lt;p&gt;## Impact
This is an approval-integrity bug. An attacker who could place or select a local wrapper binary and induce a wrapper-shaped command could get local code executed after the operator approved misleading command text.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
Wrapper resolution normalized executables by basename and extracted inner shell payload text for approval display, while execution still preserved the full wrapper argv. Approval storage and UI therefore showed text that did not match the exact command OpenClaw would execute.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now binds approvals to the exact executed argv and keeps extracted shell payload text only as secondary preview data. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32971</guid>
    </item>
    <item>
      <title>cnvd-2026-17487</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-17487</link>
      <description>cnvd-2026-17487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-17487</guid>
    </item>
    <item>
      <title>EUVD-2026-329475</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329475</link>
      <description>EUVD-2026-329475</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329475</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32971</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32971</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32971</guid>
    </item>
    <item>
      <title>GHSA-rw39-5899-8mxp — OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rw39-5899-8mxp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could display only an extracted shell payload such as `jq --version` while execution still ran a different outer wrapper argv such as `./env sh -c &amp;#39;jq --version&amp;#39;`.&lt;/p&gt;
&lt;p&gt;## Impact
This is an approval-integrity bug. An attacker who could place or select a local wrapper binary and induce a wrapper-shaped command could get local code executed after the operator approved misleading command text.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
Wrapper resolution normalized executables by basename and extracted inner shell payload text for approval display, while execution still preserved the full wrapper argv. Approval storage and UI therefore showed text that did not match the exact command OpenClaw would execute.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now binds approvals to the exact executed argv and keeps extracted shell payload text only as secondary preview data. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could display only an extracted shell payload such as `jq --version` while execution still ran a different outer wrapper argv such as `./env sh -c &amp;#39;jq --version&amp;#39;`.&lt;/p&gt;
&lt;p&gt;## Impact
This is an approval-integrity bug. An attacker who could place or select a local wrapper binary and induce a wrapper-shaped command could get local code executed after the operator approved misleading command text.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
Wrapper resolution normalized executables by basename and extracted inner shell payload text for approval display, while execution still preserved the full wrapper argv. Approval storage and UI therefore showed text that did not match the exact command OpenClaw would execute.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now binds approvals to the exact executed argv and keeps extracted shell payload text only as secondary preview data. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rw39-5899-8mxp</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0727 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0727</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0727</guid>
    </item>
  </channel>
</rss>
