<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:16:21 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41380 — OpenClaw gateway exec allow-always over-trusts positional carrier executables</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41380</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Allow-always persistence could trust wrapper carrier executables instead of the actual invoked target when commands were routed through dispatch wrappers.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A one-time approval could persist a broader future allowlist entry than the operator intended, weakening execution approval boundaries.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/exec-approvals-allowlist.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `9ec44fad39` (`Exec approvals: reject wrapper carrier allow-always targets`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Allow-always persistence could trust wrapper carrier executables instead of the actual invoked target when commands were routed through dispatch wrappers.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A one-time approval could persist a broader future allowlist entry than the operator intended, weakening execution approval boundaries.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/exec-approvals-allowlist.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `9ec44fad39` (`Exec approvals: reject wrapper carrier allow-always targets`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41380</guid>
    </item>
    <item>
      <title>EUVD-2026-307807</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307807</link>
      <description>EUVD-2026-307807</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307807</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41380</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41380</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41380</guid>
    </item>
    <item>
      <title>GHSA-p4x4-2r7f-wjxg — OpenClaw gateway exec allow-always over-trusts positional carrier executables</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p4x4-2r7f-wjxg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Allow-always persistence could trust wrapper carrier executables instead of the actual invoked target when commands were routed through dispatch wrappers.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A one-time approval could persist a broader future allowlist entry than the operator intended, weakening execution approval boundaries.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/exec-approvals-allowlist.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `9ec44fad39` (`Exec approvals: reject wrapper carrier allow-always targets`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Allow-always persistence could trust wrapper carrier executables instead of the actual invoked target when commands were routed through dispatch wrappers.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A one-time approval could persist a broader future allowlist entry than the operator intended, weakening execution approval boundaries.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`src/infra/exec-approvals-allowlist.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `9ec44fad39` (`Exec approvals: reject wrapper carrier allow-always targets`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p4x4-2r7f-wjxg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0930 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</guid>
    </item>
  </channel>
</rss>
