<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:27:02 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32979 — OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could still execute rewritten local code for interpreter and runtime commands when OpenClaw could not bind exactly one concrete local file operand during approval planning.&lt;/p&gt;
&lt;p&gt;## Impact
Deployments using node-host `system.run` approval mode could approve a benign local script and then execute different local code if that script changed before execution. This can lead to unintended local code execution as the OpenClaw runtime user.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The approval flow treated some interpreter and runtime forms as approval-backed even when it could not honestly bind a single direct local script file. That left residual approval-integrity gaps for runtime forms outside the directly bound file set.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now fails closed for approval-backed interpreter and runtime commands unless it can bind exactly one concrete local file operand, and it extends best-effort direct-file binding for additional runtime forms. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could still execute rewritten local code for interpreter and runtime commands when OpenClaw could not bind exactly one concrete local file operand during approval planning.&lt;/p&gt;
&lt;p&gt;## Impact
Deployments using node-host `system.run` approval mode could approve a benign local script and then execute different local code if that script changed before execution. This can lead to unintended local code execution as the OpenClaw runtime user.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The approval flow treated some interpreter and runtime forms as approval-backed even when it could not honestly bind a single direct local script file. That left residual approval-integrity gaps for runtime forms outside the directly bound file set.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now fails closed for approval-backed interpreter and runtime commands unless it can bind exactly one concrete local file operand, and it extends best-effort direct-file binding for additional runtime forms. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32979</guid>
    </item>
    <item>
      <title>EUVD-2026-329483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329483</link>
      <description>EUVD-2026-329483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329483</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32979</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32979</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change approved local scripts before execution to achieve unintended code execution as the OpenClaw runtime user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change approved local scripts before execution to achieve unintended code execution as the OpenClaw runtime user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32979</guid>
    </item>
    <item>
      <title>GHSA-xf99-j42q-5w5p — OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xf99-j42q-5w5p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could still execute rewritten local code for interpreter and runtime commands when OpenClaw could not bind exactly one concrete local file operand during approval planning.&lt;/p&gt;
&lt;p&gt;## Impact
Deployments using node-host `system.run` approval mode could approve a benign local script and then execute different local code if that script changed before execution. This can lead to unintended local code execution as the OpenClaw runtime user.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The approval flow treated some interpreter and runtime forms as approval-backed even when it could not honestly bind a single direct local script file. That left residual approval-integrity gaps for runtime forms outside the directly bound file set.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now fails closed for approval-backed interpreter and runtime commands unless it can bind exactly one concrete local file operand, and it extends best-effort direct-file binding for additional runtime forms. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, node-host `system.run` approvals could still execute rewritten local code for interpreter and runtime commands when OpenClaw could not bind exactly one concrete local file operand during approval planning.&lt;/p&gt;
&lt;p&gt;## Impact
Deployments using node-host `system.run` approval mode could approve a benign local script and then execute different local code if that script changed before execution. This can lead to unintended local code execution as the OpenClaw runtime user.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.3.8`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The approval flow treated some interpreter and runtime forms as approval-backed even when it could not honestly bind a single direct local script file. That left residual approval-integrity gaps for runtime forms outside the directly bound file set.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now fails closed for approval-backed interpreter and runtime commands unless it can bind exactly one concrete local file operand, and it extends best-effort direct-file binding for additional runtime forms. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xf99-j42q-5w5p</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</guid>
    </item>
  </channel>
</rss>
