<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:15:54 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41367 — OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Discord button and component interaction ingress did not consistently reapply the same guild and channel policy gates used for normal inbound messages.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Users could trigger privileged component actions from contexts that should have been blocked by Discord channel policy.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`extensions/discord/src/monitor/agent-components.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;gt;= 2026.2.14, &amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `511093d4b3` (`Discord: apply component interaction policy gates`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Discord button and component interaction ingress did not consistently reapply the same guild and channel policy gates used for normal inbound messages.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Users could trigger privileged component actions from contexts that should have been blocked by Discord channel policy.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`extensions/discord/src/monitor/agent-components.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;gt;= 2026.2.14, &amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `511093d4b3` (`Discord: apply component interaction policy gates`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41367</guid>
    </item>
    <item>
      <title>EUVD-2026-321178</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321178</link>
      <description>EUVD-2026-321178</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321178</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41367</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41367</link>
      <description>&lt;p&gt;OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41367</guid>
    </item>
    <item>
      <title>GHSA-9xc4-v83w-73v2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9xc4-v83w-73v2</link>
      <description>&lt;p&gt;OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9xc4-v83w-73v2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0930 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</guid>
    </item>
  </channel>
</rss>
