<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:44:09 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-35619 — OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The OpenAI-compatible HTTP endpoint `/v1/models` accepts bearer auth but does not enforce operator method scopes.&lt;/p&gt;
&lt;p&gt;In contrast, the WebSocket RPC path enforces `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;A caller connected with `operator.approvals` (no read scope) is rejected for `models.list` (`missing scope: operator.read`) but can still enumerate model metadata through HTTP `/v1/models`.&lt;/p&gt;
&lt;p&gt;Confirmed on current `main` at commit `06de515b6c42816b62ec752e1c221cab67b38501`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The WS control-plane path enforces role/scope checks centrally before dispatching methods. For non-admin operators, this includes required method scopes such as `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;The HTTP compatibility path for `/v1/models` performs bearer authorization and then returns model metadata; it does not apply an equivalent scope check.&lt;/p&gt;
&lt;p&gt;As reproduced, a caller with only `operator.approvals` can:&lt;/p&gt;
&lt;p&gt;1. connect successfully,
2. fail `models.list` over WS with `missing scope: operator.read`,
3. fetch `/v1/models` over HTTP with status 200 and model data.&lt;/p&gt;
&lt;p&gt;This is a cross-surface authorization inconsistency where the stricter WS policy can be bypassed via HTTP.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- Callers lacking `operator.read` can still enumerate gateway model metadata through HTTP compatibility routes.
- Breaks scope model consistency between WS RPC and HTTP surfaces.
- Weakens least-privilege expectations for operators granted non-read scopes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The OpenAI-compatible HTTP endpoint `/v1/models` accepts bearer auth but does not enforce operator method scopes.&lt;/p&gt;
&lt;p&gt;In contrast, the WebSocket RPC path enforces `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;A caller connected with `operator.approvals` (no read scope) is rejected for `models.list` (`missing scope: operator.read`) but can still enumerate model metadata through HTTP `/v1/models`.&lt;/p&gt;
&lt;p&gt;Confirmed on current `main` at commit `06de515b6c42816b62ec752e1c221cab67b38501`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The WS control-plane path enforces role/scope checks centrally before dispatching methods. For non-admin operators, this includes required method scopes such as `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;The HTTP compatibility path for `/v1/models` performs bearer authorization and then returns model metadata; it does not apply an equivalent scope check.&lt;/p&gt;
&lt;p&gt;As reproduced, a caller with only `operator.approvals` can:&lt;/p&gt;
&lt;p&gt;1. connect successfully,
2. fail `models.list` over WS with `missing scope: operator.read`,
3. fetch `/v1/models` over HTTP with status 200 and model data.&lt;/p&gt;
&lt;p&gt;This is a cross-surface authorization inconsistency where the stricter WS policy can be bypassed via HTTP.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- Callers lacking `operator.read` can still enumerate gateway model metadata through HTTP compatibility routes.
- Breaks scope model consistency between WS RPC and HTTP surfaces.
- Weakens least-privilege expectations for operators granted non-read scopes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35619</guid>
    </item>
    <item>
      <title>EUVD-2026-329497</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329497</link>
      <description>EUVD-2026-329497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329497</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35619</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35619</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through the HTTP compatibility route, bypassing the stricter WebSocket RPC authorization checks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through the HTTP compatibility route, bypassing the stricter WebSocket RPC authorization checks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35619</guid>
    </item>
    <item>
      <title>GHSA-68f8-9mhj-h2mp — OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68f8-9mhj-h2mp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The OpenAI-compatible HTTP endpoint `/v1/models` accepts bearer auth but does not enforce operator method scopes.&lt;/p&gt;
&lt;p&gt;In contrast, the WebSocket RPC path enforces `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;A caller connected with `operator.approvals` (no read scope) is rejected for `models.list` (`missing scope: operator.read`) but can still enumerate model metadata through HTTP `/v1/models`.&lt;/p&gt;
&lt;p&gt;Confirmed on current `main` at commit `06de515b6c42816b62ec752e1c221cab67b38501`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The WS control-plane path enforces role/scope checks centrally before dispatching methods. For non-admin operators, this includes required method scopes such as `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;The HTTP compatibility path for `/v1/models` performs bearer authorization and then returns model metadata; it does not apply an equivalent scope check.&lt;/p&gt;
&lt;p&gt;As reproduced, a caller with only `operator.approvals` can:&lt;/p&gt;
&lt;p&gt;1. connect successfully,
2. fail `models.list` over WS with `missing scope: operator.read`,
3. fetch `/v1/models` over HTTP with status 200 and model data.&lt;/p&gt;
&lt;p&gt;This is a cross-surface authorization inconsistency where the stricter WS policy can be bypassed via HTTP.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- Callers lacking `operator.read` can still enumerate gateway model metadata through HTTP compatibility routes.
- Breaks scope model consistency between WS RPC and HTTP surfaces.
- Weakens least-privilege expectations for operators granted non-read scopes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The OpenAI-compatible HTTP endpoint `/v1/models` accepts bearer auth but does not enforce operator method scopes.&lt;/p&gt;
&lt;p&gt;In contrast, the WebSocket RPC path enforces `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;A caller connected with `operator.approvals` (no read scope) is rejected for `models.list` (`missing scope: operator.read`) but can still enumerate model metadata through HTTP `/v1/models`.&lt;/p&gt;
&lt;p&gt;Confirmed on current `main` at commit `06de515b6c42816b62ec752e1c221cab67b38501`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The WS control-plane path enforces role/scope checks centrally before dispatching methods. For non-admin operators, this includes required method scopes such as `operator.read` for `models.list`.&lt;/p&gt;
&lt;p&gt;The HTTP compatibility path for `/v1/models` performs bearer authorization and then returns model metadata; it does not apply an equivalent scope check.&lt;/p&gt;
&lt;p&gt;As reproduced, a caller with only `operator.approvals` can:&lt;/p&gt;
&lt;p&gt;1. connect successfully,
2. fail `models.list` over WS with `missing scope: operator.read`,
3. fetch `/v1/models` over HTTP with status 200 and model data.&lt;/p&gt;
&lt;p&gt;This is a cross-surface authorization inconsistency where the stricter WS policy can be bypassed via HTTP.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- Callers lacking `operator.read` can still enumerate gateway model metadata through HTTP compatibility routes.
- Breaks scope model consistency between WS RPC and HTTP surfaces.
- Weakens least-privilege expectations for operators granted non-read scopes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68f8-9mhj-h2mp</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1065 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065</guid>
    </item>
  </channel>
</rss>
