<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:24:17 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-44995 — OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-44995</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.4.20`
- Patched version: `2026.4.20`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Workspace MCP stdio configuration could pass dangerous process-startup environment variables such as `NODE_OPTIONS`, `LD_PRELOAD`, or `BASH_ENV` to the spawned MCP server process. In a malicious workspace, this could make the MCP child load attacker-controlled code when the operator starts a session that uses that MCP server.&lt;/p&gt;
&lt;p&gt;The impact is limited to local/workspace trust boundaries and requires the operator to run OpenClaw in a workspace containing the malicious MCP configuration. Severity is therefore medium, not high/critical.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now filters MCP stdio environment entries through the host environment safety denylist before spawning stdio MCP servers.&lt;/p&gt;
&lt;p&gt;Fix commits:&lt;/p&gt;
&lt;p&gt;- `62fa5071896e95edc7f67d1cebc70a2859e283af`
- `85d86ebc4bf3d2226d39d132a484f4f7a299fa1b`&lt;/p&gt;
&lt;p&gt;## Release&lt;/p&gt;
&lt;p&gt;Fixed in OpenClaw `2026.4.20`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.4.20`
- Patched version: `2026.4.20`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Workspace MCP stdio configuration could pass dangerous process-startup environment variables such as `NODE_OPTIONS`, `LD_PRELOAD`, or `BASH_ENV` to the spawned MCP server process. In a malicious workspace, this could make the MCP child load attacker-controlled code when the operator starts a session that uses that MCP server.&lt;/p&gt;
&lt;p&gt;The impact is limited to local/workspace trust boundaries and requires the operator to run OpenClaw in a workspace containing the malicious MCP configuration. Severity is therefore medium, not high/critical.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now filters MCP stdio environment entries through the host environment safety denylist before spawning stdio MCP servers.&lt;/p&gt;
&lt;p&gt;Fix commits:&lt;/p&gt;
&lt;p&gt;- `62fa5071896e95edc7f67d1cebc70a2859e283af`
- `85d86ebc4bf3d2226d39d132a484f4f7a299fa1b`&lt;/p&gt;
&lt;p&gt;## Release&lt;/p&gt;
&lt;p&gt;Fixed in OpenClaw `2026.4.20`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-44995</guid>
    </item>
    <item>
      <title>EUVD-2026-310008</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310008</link>
      <description>EUVD-2026-310008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310008</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44995</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44995</link>
      <description>&lt;p&gt;OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawned MCP server processes, enabling code injection when operators start sessions using those servers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawned MCP server processes, enabling code injection when operators start sessions using those servers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44995</guid>
    </item>
    <item>
      <title>GHSA-mj59-h3q9-ghfh — OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mj59-h3q9-ghfh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.4.20`
- Patched version: `2026.4.20`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Workspace MCP stdio configuration could pass dangerous process-startup environment variables such as `NODE_OPTIONS`, `LD_PRELOAD`, or `BASH_ENV` to the spawned MCP server process. In a malicious workspace, this could make the MCP child load attacker-controlled code when the operator starts a session that uses that MCP server.&lt;/p&gt;
&lt;p&gt;The impact is limited to local/workspace trust boundaries and requires the operator to run OpenClaw in a workspace containing the malicious MCP configuration. Severity is therefore medium, not high/critical.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now filters MCP stdio environment entries through the host environment safety denylist before spawning stdio MCP servers.&lt;/p&gt;
&lt;p&gt;Fix commits:&lt;/p&gt;
&lt;p&gt;- `62fa5071896e95edc7f67d1cebc70a2859e283af`
- `85d86ebc4bf3d2226d39d132a484f4f7a299fa1b`&lt;/p&gt;
&lt;p&gt;## Release&lt;/p&gt;
&lt;p&gt;Fixed in OpenClaw `2026.4.20`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` (npm)
- Affected versions: `&amp;lt; 2026.4.20`
- Patched version: `2026.4.20`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Workspace MCP stdio configuration could pass dangerous process-startup environment variables such as `NODE_OPTIONS`, `LD_PRELOAD`, or `BASH_ENV` to the spawned MCP server process. In a malicious workspace, this could make the MCP child load attacker-controlled code when the operator starts a session that uses that MCP server.&lt;/p&gt;
&lt;p&gt;The impact is limited to local/workspace trust boundaries and requires the operator to run OpenClaw in a workspace containing the malicious MCP configuration. Severity is therefore medium, not high/critical.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now filters MCP stdio environment entries through the host environment safety denylist before spawning stdio MCP servers.&lt;/p&gt;
&lt;p&gt;Fix commits:&lt;/p&gt;
&lt;p&gt;- `62fa5071896e95edc7f67d1cebc70a2859e283af`
- `85d86ebc4bf3d2226d39d132a484f4f7a299fa1b`&lt;/p&gt;
&lt;p&gt;## Release&lt;/p&gt;
&lt;p&gt;Fixed in OpenClaw `2026.4.20`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mj59-h3q9-ghfh</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1227 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1227</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren oder offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren oder offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1227</guid>
    </item>
  </channel>
</rss>
