<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:05:48 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-35664 — OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35664</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Feishu Raw card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Feishu raw card sends could previously mint legacy callback payloads that bypassed DM pairing and let unpaired recipients reach callback handling. Commit `81c45976db532324b5a0918a70decc19520dc354` rejects legacy raw-card command payloads so callbacks stay on the normal paired path.&lt;/p&gt;
&lt;p&gt;Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `81c45976db532324b5a0918a70decc19520dc354`.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `81c45976db532324b5a0918a70decc19520dc354`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Feishu Raw card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Feishu raw card sends could previously mint legacy callback payloads that bypassed DM pairing and let unpaired recipients reach callback handling. Commit `81c45976db532324b5a0918a70decc19520dc354` rejects legacy raw-card command payloads so callbacks stay on the normal paired path.&lt;/p&gt;
&lt;p&gt;Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `81c45976db532324b5a0918a70decc19520dc354`.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `81c45976db532324b5a0918a70decc19520dc354`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35664</guid>
    </item>
    <item>
      <title>EUVD-2026-329541</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329541</link>
      <description>EUVD-2026-329541</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329541</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35664</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35664</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy callback payloads. Attackers can send raw card commands to bypass DM pairing restrictions and reach callback handling without proper authorization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy callback payloads. Attackers can send raw card commands to bypass DM pairing restrictions and reach callback handling without proper authorization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35664</guid>
    </item>
    <item>
      <title>GHSA-77w2-crqv-cmv3 — OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-77w2-crqv-cmv3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Feishu Raw card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Feishu raw card sends could previously mint legacy callback payloads that bypassed DM pairing and let unpaired recipients reach callback handling. Commit `81c45976db532324b5a0918a70decc19520dc354` rejects legacy raw-card command payloads so callbacks stay on the normal paired path.&lt;/p&gt;
&lt;p&gt;Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `81c45976db532324b5a0918a70decc19520dc354`.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `81c45976db532324b5a0918a70decc19520dc354`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Feishu Raw card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Affected versions: `&amp;lt;= 2026.3.24`
- First patched version: `2026.3.25`
- Latest published npm version at verification time: `2026.3.24`&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Feishu raw card sends could previously mint legacy callback payloads that bypassed DM pairing and let unpaired recipients reach callback handling. Commit `81c45976db532324b5a0918a70decc19520dc354` rejects legacy raw-card command payloads so callbacks stay on the normal paired path.&lt;/p&gt;
&lt;p&gt;Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `81c45976db532324b5a0918a70decc19520dc354`.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `81c45976db532324b5a0918a70decc19520dc354`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-77w2-crqv-cmv3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0884 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0884</guid>
    </item>
  </channel>
</rss>
