<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 13:54:17 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41370 — OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Normalized severity: medium
- Assessment: v2026.3.28 ACP dispatch still reads attachment paths outside the guarded attachment-cache or root checks, and the root-enforcement fix is not yet shipped.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `566fb73d9da2d73c0be0d9b8e5b762e4dcd8e81d` — 2026-03-30T14:04:02+01:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @north-echo for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Normalized severity: medium
- Assessment: v2026.3.28 ACP dispatch still reads attachment paths outside the guarded attachment-cache or root checks, and the root-enforcement fix is not yet shipped.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `566fb73d9da2d73c0be0d9b8e5b762e4dcd8e81d` — 2026-03-30T14:04:02+01:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @north-echo for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41370</guid>
    </item>
    <item>
      <title>EUVD-2026-307874</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307874</link>
      <description>EUVD-2026-307874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307874</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41370</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41370</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41370</guid>
    </item>
    <item>
      <title>GHSA-pmg8-9xxh-v2wv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pmg8-9xxh-v2wv</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pmg8-9xxh-v2wv</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</guid>
    </item>
  </channel>
</rss>
