<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 20:46:51 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-43575 — OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43575</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Sandbox noVNC helper route exposed interactive browser session credentials.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;gt;= 2026.2.21 &amp;lt; 2026.4.10`
- Patched versions: `&amp;gt;= 2026.4.10`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The sandbox noVNC helper route could be reached without the intended bridge authentication, exposing an interactive browser session surface.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix gates the sandbox noVNC helper route behind bridge authentication.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #63882. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `8dfbf3268bd224b7377d1ecca77a445100746085`
- PR: #63882&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Sandbox noVNC helper route exposed interactive browser session credentials.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;gt;= 2026.2.21 &amp;lt; 2026.4.10`
- Patched versions: `&amp;gt;= 2026.4.10`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The sandbox noVNC helper route could be reached without the intended bridge authentication, exposing an interactive browser session surface.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix gates the sandbox noVNC helper route behind bridge authentication.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #63882. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `8dfbf3268bd224b7377d1ecca77a445100746085`
- PR: #63882&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43575</guid>
    </item>
    <item>
      <title>EUVD-2026-308995</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308995</link>
      <description>EUVD-2026-308995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308995</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43575</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43575</link>
      <description>&lt;p&gt;OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43575</guid>
    </item>
    <item>
      <title>GHSA-xm83-jc96-gw22</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xm83-jc96-gw22</link>
      <description>&lt;p&gt;OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xm83-jc96-gw22</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</guid>
    </item>
  </channel>
</rss>
