<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:26:05 +0000</lastBuildDate>
    <item>
      <title>fkie_cve-2026-39398</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39398</link>
      <description>&lt;p&gt;Rejected reason: The affected product and advisory are not public.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: The affected product and advisory are not public.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39398</guid>
    </item>
    <item>
      <title>GHSA-7853-gqqm-vcwx — openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7853-gqqm-vcwx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw-claude-bridge&lt;/p&gt;
&lt;p&gt;## Affected&lt;/p&gt;
&lt;p&gt;openclaw-claude-bridge v1.1.0&lt;/p&gt;
&lt;p&gt;## Issue&lt;/p&gt;
&lt;p&gt;v1.1.0 spawns the Claude Code CLI subprocess with `--allowed-tools &amp;#34;&amp;#34;` and the release notes + README claim this **&amp;#34;disables all CLI tools&amp;#34;** for sandboxing. This claim is incorrect.&lt;/p&gt;
&lt;p&gt;Per the Claude Code CLI documentation, `--allowed-tools` (alias `--allowedTools`) is an **auto-approve allowlist** of tools that execute without permission prompts — NOT a restriction on which tools are available. The correct flag to restrict the available tool set is `--tools`:&lt;/p&gt;
&lt;p&gt;&amp;gt; `--tools &amp;lt;tools...&amp;gt;`  Specify the list of available tools from the built-in set. **Use `&amp;#34;&amp;#34;` to disable all tools**, `&amp;#34;default&amp;#34;` to use all tools, or specify tool names (e.g. `&amp;#34;Bash,Edit,Read&amp;#34;`).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- All CLI tools (Read/Write/Bash/WebFetch/...) remain nominally available to the spawned subprocess.
- Actual execution behavior in `--print` non-interactive mode depends on undocumented CLI defaults (may auto-deny, may error out, may hang).
- Users who deploy the bridge behind any interface that forwards untrusted prompts (e.g., publicly exposed OpenClaw gateway, automated pipelines with web-fetched context, agents that consume tool results from other systems) may be relying on a sandbox that does not exist.&lt;/p&gt;
&lt;p&gt;The README explicitly makes a security claim the code does not uphold, creating a false sense of safety for downstream operators. If the underlying CLI behavior changes in a future version to auto-allow tools in `--print` mode, prompt-injection attacks co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw-claude-bridge&lt;/p&gt;
&lt;p&gt;## Affected&lt;/p&gt;
&lt;p&gt;openclaw-claude-bridge v1.1.0&lt;/p&gt;
&lt;p&gt;## Issue&lt;/p&gt;
&lt;p&gt;v1.1.0 spawns the Claude Code CLI subprocess with `--allowed-tools &amp;#34;&amp;#34;` and the release notes + README claim this **&amp;#34;disables all CLI tools&amp;#34;** for sandboxing. This claim is incorrect.&lt;/p&gt;
&lt;p&gt;Per the Claude Code CLI documentation, `--allowed-tools` (alias `--allowedTools`) is an **auto-approve allowlist** of tools that execute without permission prompts — NOT a restriction on which tools are available. The correct flag to restrict the available tool set is `--tools`:&lt;/p&gt;
&lt;p&gt;&amp;gt; `--tools &amp;lt;tools...&amp;gt;`  Specify the list of available tools from the built-in set. **Use `&amp;#34;&amp;#34;` to disable all tools**, `&amp;#34;default&amp;#34;` to use all tools, or specify tool names (e.g. `&amp;#34;Bash,Edit,Read&amp;#34;`).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- All CLI tools (Read/Write/Bash/WebFetch/...) remain nominally available to the spawned subprocess.
- Actual execution behavior in `--print` non-interactive mode depends on undocumented CLI defaults (may auto-deny, may error out, may hang).
- Users who deploy the bridge behind any interface that forwards untrusted prompts (e.g., publicly exposed OpenClaw gateway, automated pipelines with web-fetched context, agents that consume tool results from other systems) may be relying on a sandbox that does not exist.&lt;/p&gt;
&lt;p&gt;The README explicitly makes a security claim the code does not uphold, creating a false sense of safety for downstream operators. If the underlying CLI behavior changes in a future version to auto-allow tools in `--print` mode, prompt-injection attacks co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7853-gqqm-vcwx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1005 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1005</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1005</guid>
    </item>
  </channel>
</rss>
