<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:28:55 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32977 — OpenClaw: Sandbox `writeFile` commit could race outside the validated path</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32977</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path.&lt;/p&gt;
&lt;p&gt;## Impact
This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path.&lt;/p&gt;
&lt;p&gt;## Impact
This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32977</guid>
    </item>
    <item>
      <title>cnvd-2026-17185</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-17185</link>
      <description>cnvd-2026-17185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-17185</guid>
    </item>
    <item>
      <title>EUVD-2026-329481</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329481</link>
      <description>EUVD-2026-329481</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329481</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32977</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32977</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32977</guid>
    </item>
    <item>
      <title>GHSA-xvx8-77m6-gwg6 — OpenClaw: Sandbox `writeFile` commit could race outside the validated path</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xvx8-77m6-gwg6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path.&lt;/p&gt;
&lt;p&gt;## Impact
This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path.&lt;/p&gt;
&lt;p&gt;## Impact
This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xvx8-77m6-gwg6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</guid>
    </item>
  </channel>
</rss>
