<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 23:01:19 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41371 — OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `chat.send` path reused command authorization to trigger `/reset` session rotation even though direct session reset is an admin-only control-plane operation.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A write-scoped gateway caller could rotate a target session, archive the prior transcript state, and force a new session id without admin scope.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/gateway/server-methods/chat.ts, src/auto-reply/reply/session.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `be00fcfccb` (`Gateway: align chat.send reset scope checks`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `chat.send` path reused command authorization to trigger `/reset` session rotation even though direct session reset is an admin-only control-plane operation.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A write-scoped gateway caller could rotate a target session, archive the prior transcript state, and force a new session id without admin scope.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/gateway/server-methods/chat.ts, src/auto-reply/reply/session.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `be00fcfccb` (`Gateway: align chat.send reset scope checks`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41371</guid>
    </item>
    <item>
      <title>EUVD-2026-293288</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-293288</link>
      <description>EUVD-2026-293288</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-293288</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41371</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41371</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41371</guid>
    </item>
    <item>
      <title>GHSA-592j-4mrx-v257</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-592j-4mrx-v257</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-592j-4mrx-v257</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0930 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</guid>
    </item>
  </channel>
</rss>
