<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:04:29 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-43580 — OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Browser press/type interaction routes missed complete navigation guard coverage.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.10`
- Patched versions: `&amp;gt;= 2026.4.10`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Some browser press/type style interactions could trigger navigation without complete post-action SSRF policy enforcement.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix applies a three-phase interaction navigation guard to navigation-capable interactions, including pressKey and type submit flows.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #62023 and #63226 and #63889. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `049acf23cb03e1b92f5c71cd99c6ec5f35cc56fe`
- `5f5b3d733bdd791cb457f838514179e1288b10b3`
- `e0b8ddc1a55185aff1cf9e0e095014d2e4f1d894`
- PR: #62023, #63226, #63889&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Browser press/type interaction routes missed complete navigation guard coverage.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.10`
- Patched versions: `&amp;gt;= 2026.4.10`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Some browser press/type style interactions could trigger navigation without complete post-action SSRF policy enforcement.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix applies a three-phase interaction navigation guard to navigation-capable interactions, including pressKey and type submit flows.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #62023 and #63226 and #63889. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `049acf23cb03e1b92f5c71cd99c6ec5f35cc56fe`
- `5f5b3d733bdd791cb457f838514179e1288b10b3`
- `e0b8ddc1a55185aff1cf9e0e095014d2e4f1d894`
- PR: #62023, #63226, #63889&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-43580</guid>
    </item>
    <item>
      <title>EUVD-2026-308935</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308935</link>
      <description>EUVD-2026-308935</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308935</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43580</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43580</link>
      <description>&lt;p&gt;OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit flows, can bypass post-action security checks to execute unauthorized navigation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit flows, can bypass post-action security checks to execute unauthorized navigation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43580</guid>
    </item>
    <item>
      <title>GHSA-536q-mj95-h29h — OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-536q-mj95-h29h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Browser press/type interaction routes missed complete navigation guard coverage.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.10`
- Patched versions: `&amp;gt;= 2026.4.10`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Some browser press/type style interactions could trigger navigation without complete post-action SSRF policy enforcement.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix applies a three-phase interaction navigation guard to navigation-capable interactions, including pressKey and type submit flows.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #62023 and #63226 and #63889. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `049acf23cb03e1b92f5c71cd99c6ec5f35cc56fe`
- `5f5b3d733bdd791cb457f838514179e1288b10b3`
- `e0b8ddc1a55185aff1cf9e0e095014d2e4f1d894`
- PR: #62023, #63226, #63889&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Browser press/type interaction routes missed complete navigation guard coverage.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.10`
- Patched versions: `&amp;gt;= 2026.4.10`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Some browser press/type style interactions could trigger navigation without complete post-action SSRF policy enforcement.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix applies a three-phase interaction navigation guard to navigation-capable interactions, including pressKey and type submit flows.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #62023 and #63226 and #63889. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `049acf23cb03e1b92f5c71cd99c6ec5f35cc56fe`
- `5f5b3d733bdd791cb457f838514179e1288b10b3`
- `e0b8ddc1a55185aff1cf9e0e095014d2e4f1d894`
- PR: #62023, #63226, #63889&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-536q-mj95-h29h</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1161 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1161</guid>
    </item>
  </channel>
</rss>
