<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:11:44 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-43574 — OpenClaw: Empty approver lists could grant explicit approval authorization</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Empty approver lists could grant explicit approval authorization.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.12`
- Patched versions: `&amp;gt;= 2026.4.12`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @anshumanbh for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Empty approver lists could grant explicit approval authorization.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.12`
- Patched versions: `&amp;gt;= 2026.4.12`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @anshumanbh for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43574</guid>
    </item>
    <item>
      <title>EUVD-2026-308523</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308523</link>
      <description>EUVD-2026-308523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308523</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43574</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43574</link>
      <description>&lt;p&gt;OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43574</guid>
    </item>
    <item>
      <title>GHSA-49cg-279w-m73x — OpenClaw: Empty approver lists could grant explicit approval authorization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-49cg-279w-m73x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Empty approver lists could grant explicit approval authorization.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.12`
- Patched versions: `&amp;gt;= 2026.4.12`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @anshumanbh for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Empty approver lists could grant explicit approval authorization.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.12`
- Patched versions: `&amp;gt;= 2026.4.12`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @anshumanbh for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-49cg-279w-m73x</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1174 — OpenClaw: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1174</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in OpenClaw ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in OpenClaw ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1174</guid>
    </item>
  </channel>
</rss>
