<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 20:46:21 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-33581 — OpenClaw's message tool media parameter bypasses tool policy filesystem isolation</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-33581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The message tool accepted `mediaUrl` and `fileUrl` aliases without applying the same sandbox localRoots validation as the canonical media path handling.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A caller constrained to sandbox media roots could read arbitrary local files by routing them through the alias parameters.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/outbound/message-action-params.ts, src/infra/outbound/message-action-runner.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt; 2026.3.24`
- Patched: `&amp;gt;= 2026.3.24`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `1d7cb6fc03` (`fix: close sandbox media root bypass for mediaUrl/fileUrl aliases`).&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The message tool accepted `mediaUrl` and `fileUrl` aliases without applying the same sandbox localRoots validation as the canonical media path handling.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A caller constrained to sandbox media roots could read arbitrary local files by routing them through the alias parameters.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/outbound/message-action-params.ts, src/infra/outbound/message-action-runner.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt; 2026.3.24`
- Patched: `&amp;gt;= 2026.3.24`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `1d7cb6fc03` (`fix: close sandbox media root bypass for mediaUrl/fileUrl aliases`).&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-33581</guid>
    </item>
    <item>
      <title>cnvd-2026-17892</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-17892</link>
      <description>cnvd-2026-17892</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-17892</guid>
    </item>
    <item>
      <title>EUVD-2026-374802</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374802</link>
      <description>EUVD-2026-374802</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374802</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33581</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33581</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers can exploit this by routing file requests through unvalidated alias parameters to access files outside the intended sandbox directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers can exploit this by routing file requests through unvalidated alias parameters to access files outside the intended sandbox directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33581</guid>
    </item>
    <item>
      <title>GHSA-v8wv-jg3q-qwpq — OpenClaw's message tool media parameter bypasses tool policy filesystem isolation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8wv-jg3q-qwpq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The message tool accepted `mediaUrl` and `fileUrl` aliases without applying the same sandbox localRoots validation as the canonical media path handling.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A caller constrained to sandbox media roots could read arbitrary local files by routing them through the alias parameters.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/outbound/message-action-params.ts, src/infra/outbound/message-action-runner.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt; 2026.3.24`
- Patched: `&amp;gt;= 2026.3.24`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `1d7cb6fc03` (`fix: close sandbox media root bypass for mediaUrl/fileUrl aliases`).&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The message tool accepted `mediaUrl` and `fileUrl` aliases without applying the same sandbox localRoots validation as the canonical media path handling.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A caller constrained to sandbox media roots could read arbitrary local files by routing them through the alias parameters.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/outbound/message-action-params.ts, src/infra/outbound/message-action-runner.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt; 2026.3.24`
- Patched: `&amp;gt;= 2026.3.24`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `1d7cb6fc03` (`fix: close sandbox media root bypass for mediaUrl/fileUrl aliases`).&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8wv-jg3q-qwpq</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0930 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</guid>
    </item>
  </channel>
</rss>
