<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:26:37 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-43535 — OpenClaw: Collect-mode queue batches could reuse the last sender authorization context</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43535</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Collect-mode queue batches could reuse the last sender authorization context.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.14`
- Patched versions: `&amp;gt;= 2026.4.14`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Collect-mode queued messages from different senders could be drained as one batch using the final sender&amp;#39;s authorization context, allowing earlier messages to inherit a more privileged context.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix splits collect-mode batches by sender authorization context before dispatch, preserving each message&amp;#39;s own trust state.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #66024. The first stable tag containing the fix is `v2026.4.14`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `43d4be902755c970b3d15608679761877718da69`
- PR: #66024&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.14 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Collect-mode queue batches could reuse the last sender authorization context.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.14`
- Patched versions: `&amp;gt;= 2026.4.14`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Collect-mode queued messages from different senders could be drained as one batch using the final sender&amp;#39;s authorization context, allowing earlier messages to inherit a more privileged context.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix splits collect-mode batches by sender authorization context before dispatch, preserving each message&amp;#39;s own trust state.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #66024. The first stable tag containing the fix is `v2026.4.14`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `43d4be902755c970b3d15608679761877718da69`
- PR: #66024&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.14 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43535</guid>
    </item>
    <item>
      <title>EUVD-2026-308521</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308521</link>
      <description>EUVD-2026-308521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308521</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43535</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43535</link>
      <description>&lt;p&gt;OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender&amp;#39;s authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a more privileged sender&amp;#39;s context, causing earlier messages to execute with elevated permissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender&amp;#39;s authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a more privileged sender&amp;#39;s context, causing earlier messages to execute with elevated permissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43535</guid>
    </item>
    <item>
      <title>GHSA-jwrq-8g5x-5fhm — OpenClaw: Collect-mode queue batches could reuse the last sender authorization context</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jwrq-8g5x-5fhm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Collect-mode queue batches could reuse the last sender authorization context.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.14`
- Patched versions: `&amp;gt;= 2026.4.14`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Collect-mode queued messages from different senders could be drained as one batch using the final sender&amp;#39;s authorization context, allowing earlier messages to inherit a more privileged context.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix splits collect-mode batches by sender authorization context before dispatch, preserving each message&amp;#39;s own trust state.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #66024. The first stable tag containing the fix is `v2026.4.14`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `43d4be902755c970b3d15608679761877718da69`
- PR: #66024&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.14 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Collect-mode queue batches could reuse the last sender authorization context.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.14`
- Patched versions: `&amp;gt;= 2026.4.14`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Collect-mode queued messages from different senders could be drained as one batch using the final sender&amp;#39;s authorization context, allowing earlier messages to inherit a more privileged context.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix splits collect-mode batches by sender authorization context before dispatch, preserving each message&amp;#39;s own trust state.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #66024. The first stable tag containing the fix is `v2026.4.14`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `43d4be902755c970b3d15608679761877718da69`
- PR: #66024&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.14 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jwrq-8g5x-5fhm</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</guid>
    </item>
  </channel>
</rss>
