<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:20:28 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-34511 — OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-34511</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Before OpenClaw 2026.4.2, the Gemini OAuth flow reused the PKCE verifier as the OAuth `state` value. Because the provider reflected `state` back in the redirect URL, the verifier could be exposed alongside the authorization code.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Anyone who could capture the redirect URL could learn both the authorization code and the PKCE verifier, defeating PKCE&amp;#39;s interception protection for that flow and enabling token redemption.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.4.1`
- Patched versions: `&amp;gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `a26f4d0f3ef0757db6c6c40277cc06a5de76c52f` — separate OAuth state from the PKCE verifier&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @BG0ECV for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Before OpenClaw 2026.4.2, the Gemini OAuth flow reused the PKCE verifier as the OAuth `state` value. Because the provider reflected `state` back in the redirect URL, the verifier could be exposed alongside the authorization code.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Anyone who could capture the redirect URL could learn both the authorization code and the PKCE verifier, defeating PKCE&amp;#39;s interception protection for that flow and enabling token redemption.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.4.1`
- Patched versions: `&amp;gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `a26f4d0f3ef0757db6c6c40277cc06a5de76c52f` — separate OAuth state from the PKCE verifier&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @BG0ECV for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-34511</guid>
    </item>
    <item>
      <title>EUVD-2026-374807</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374807</link>
      <description>EUVD-2026-374807</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374807</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34511</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34511</link>
      <description>&lt;p&gt;OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34511</guid>
    </item>
    <item>
      <title>GHSA-9jpj-g8vv-j5mf — OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9jpj-g8vv-j5mf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Before OpenClaw 2026.4.2, the Gemini OAuth flow reused the PKCE verifier as the OAuth `state` value. Because the provider reflected `state` back in the redirect URL, the verifier could be exposed alongside the authorization code.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Anyone who could capture the redirect URL could learn both the authorization code and the PKCE verifier, defeating PKCE&amp;#39;s interception protection for that flow and enabling token redemption.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.4.1`
- Patched versions: `&amp;gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `a26f4d0f3ef0757db6c6c40277cc06a5de76c52f` — separate OAuth state from the PKCE verifier&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @BG0ECV for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Before OpenClaw 2026.4.2, the Gemini OAuth flow reused the PKCE verifier as the OAuth `state` value. Because the provider reflected `state` back in the redirect URL, the verifier could be exposed alongside the authorization code.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Anyone who could capture the redirect URL could learn both the authorization code and the PKCE verifier, defeating PKCE&amp;#39;s interception protection for that flow and enabling token redemption.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt;= 2026.4.1`
- Patched versions: `&amp;gt;= 2026.4.2`
- Latest published npm version: `2026.4.1`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `a26f4d0f3ef0757db6c6c40277cc06a5de76c52f` — separate OAuth state from the PKCE verifier&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @BG0ECV for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9jpj-g8vv-j5mf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0980 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0980</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Daten zu manipulieren, Sicherheitsmechanismen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen..&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Daten zu manipulieren, Sicherheitsmechanismen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen..&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0980</guid>
    </item>
  </channel>
</rss>
