<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:27:41 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41402 — OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41402</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Zalo webhook replay cache cross-target messageId scope bypass&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: low
- Assessment: v2026.3.28 replay dedupe is still keyed too broadly, but the issue should stay scoped to authenticated sibling-target delivery paths rather than arbitrary unauthenticated attackers.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `4d038bb242c11f39e45f6a4bde400e5fd42e4ebf` — 2026-03-31T19:33:57+09:00&lt;/p&gt;
&lt;p&gt;## Release Process Note
- The fix is already present in released version `2026.3.31`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.&lt;/p&gt;
&lt;p&gt;Thanks @smaeljaish771 for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Zalo webhook replay cache cross-target messageId scope bypass&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: low
- Assessment: v2026.3.28 replay dedupe is still keyed too broadly, but the issue should stay scoped to authenticated sibling-target delivery paths rather than arbitrary unauthenticated attackers.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `4d038bb242c11f39e45f6a4bde400e5fd42e4ebf` — 2026-03-31T19:33:57+09:00&lt;/p&gt;
&lt;p&gt;## Release Process Note
- The fix is already present in released version `2026.3.31`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.&lt;/p&gt;
&lt;p&gt;Thanks @smaeljaish771 for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41402</guid>
    </item>
    <item>
      <title>EUVD-2026-307826</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307826</link>
      <description>EUVD-2026-307826</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307826</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41402</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41402</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the same messageId. Attackers can exploit overly broad cache keying to bypass replay protection and deliver duplicate webhook messages to unintended targets.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the same messageId. Attackers can exploit overly broad cache keying to bypass replay protection and deliver duplicate webhook messages to unintended targets.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41402</guid>
    </item>
    <item>
      <title>GHSA-hhq4-97c2-p447 — OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hhq4-97c2-p447</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Zalo webhook replay cache cross-target messageId scope bypass&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: low
- Assessment: v2026.3.28 replay dedupe is still keyed too broadly, but the issue should stay scoped to authenticated sibling-target delivery paths rather than arbitrary unauthenticated attackers.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `4d038bb242c11f39e45f6a4bde400e5fd42e4ebf` — 2026-03-31T19:33:57+09:00&lt;/p&gt;
&lt;p&gt;## Release Process Note
- The fix is already present in released version `2026.3.31`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.&lt;/p&gt;
&lt;p&gt;Thanks @smaeljaish771 for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Zalo webhook replay cache cross-target messageId scope bypass&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: low
- Assessment: v2026.3.28 replay dedupe is still keyed too broadly, but the issue should stay scoped to authenticated sibling-target delivery paths rather than arbitrary unauthenticated attackers.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `4d038bb242c11f39e45f6a4bde400e5fd42e4ebf` — 2026-03-31T19:33:57+09:00&lt;/p&gt;
&lt;p&gt;## Release Process Note
- The fix is already present in released version `2026.3.31`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.&lt;/p&gt;
&lt;p&gt;Thanks @smaeljaish771 for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hhq4-97c2-p447</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</guid>
    </item>
  </channel>
</rss>
