<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:28:42 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-45004 — OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key res…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-45004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s bundled plugin setup resolver could fall back to `process.cwd()` while resolving provider setup metadata. If a user ran an OpenClaw command from an attacker-controlled repository containing `extensions/&amp;lt;plugin&amp;gt;/setup-api.js`, OpenClaw could load and execute that JavaScript during ordinary provider/model status resolution.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This is arbitrary JavaScript execution in the OpenClaw process under the current user account. A malicious repository could run code when the user executed commands such as provider/model inspection from that directory. The issue does not require gateway network exposure, but it does require user interaction: the user must run OpenClaw from a directory containing the attacker-controlled setup file.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` on npm
- Affected: versions before `2026.4.23`
- Fixed: `2026.4.23`
- Latest stable verified fixed: `openclaw@2026.4.23`, tag `v2026.4.23`&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now resolves bundled setup fallbacks only from the canonical package/repository root and no longer includes `process.cwd()` as a trusted setup-api search root. A regression test verifies that a workspace-local `extensions/&amp;lt;plugin&amp;gt;/setup-api.js` is not loaded through provider setup resolution.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `993781e6e6eaf50f033cfc3e3bf4f47059740707` (`fix(plugins): ignore cwd setup-api fallback`)&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Severity remains `high` because successful exploitation allows arbitrary code execution under the user ru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s bundled plugin setup resolver could fall back to `process.cwd()` while resolving provider setup metadata. If a user ran an OpenClaw command from an attacker-controlled repository containing `extensions/&amp;lt;plugin&amp;gt;/setup-api.js`, OpenClaw could load and execute that JavaScript during ordinary provider/model status resolution.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This is arbitrary JavaScript execution in the OpenClaw process under the current user account. A malicious repository could run code when the user executed commands such as provider/model inspection from that directory. The issue does not require gateway network exposure, but it does require user interaction: the user must run OpenClaw from a directory containing the attacker-controlled setup file.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` on npm
- Affected: versions before `2026.4.23`
- Fixed: `2026.4.23`
- Latest stable verified fixed: `openclaw@2026.4.23`, tag `v2026.4.23`&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now resolves bundled setup fallbacks only from the canonical package/repository root and no longer includes `process.cwd()` as a trusted setup-api search root. A regression test verifies that a workspace-local `extensions/&amp;lt;plugin&amp;gt;/setup-api.js` is not loaded through provider setup resolution.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `993781e6e6eaf50f033cfc3e3bf4f47059740707` (`fix(plugins): ignore cwd setup-api fallback`)&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Severity remains `high` because successful exploitation allows arbitrary code execution under the user ru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-45004</guid>
    </item>
    <item>
      <title>cnvd-2026-22281</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-22281</link>
      <description>cnvd-2026-22281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-22281</guid>
    </item>
    <item>
      <title>EUVD-2026-310044</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310044</link>
      <description>EUVD-2026-310044</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310044</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45004</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45004</link>
      <description>&lt;p&gt;OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under the current user account by placing a malicious extensions/&amp;lt;plugin&amp;gt;/setup-api.js file in a repository and convincing a user to run OpenClaw commands from that directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under the current user account by placing a malicious extensions/&amp;lt;plugin&amp;gt;/setup-api.js file in a repository and convincing a user to run OpenClaw commands from that directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45004</guid>
    </item>
    <item>
      <title>GHSA-r39h-4c2p-3jxp — OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key res…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r39h-4c2p-3jxp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s bundled plugin setup resolver could fall back to `process.cwd()` while resolving provider setup metadata. If a user ran an OpenClaw command from an attacker-controlled repository containing `extensions/&amp;lt;plugin&amp;gt;/setup-api.js`, OpenClaw could load and execute that JavaScript during ordinary provider/model status resolution.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This is arbitrary JavaScript execution in the OpenClaw process under the current user account. A malicious repository could run code when the user executed commands such as provider/model inspection from that directory. The issue does not require gateway network exposure, but it does require user interaction: the user must run OpenClaw from a directory containing the attacker-controlled setup file.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` on npm
- Affected: versions before `2026.4.23`
- Fixed: `2026.4.23`
- Latest stable verified fixed: `openclaw@2026.4.23`, tag `v2026.4.23`&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now resolves bundled setup fallbacks only from the canonical package/repository root and no longer includes `process.cwd()` as a trusted setup-api search root. A regression test verifies that a workspace-local `extensions/&amp;lt;plugin&amp;gt;/setup-api.js` is not loaded through provider setup resolution.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `993781e6e6eaf50f033cfc3e3bf4f47059740707` (`fix(plugins): ignore cwd setup-api fallback`)&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Severity remains `high` because successful exploitation allows arbitrary code execution under the user ru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s bundled plugin setup resolver could fall back to `process.cwd()` while resolving provider setup metadata. If a user ran an OpenClaw command from an attacker-controlled repository containing `extensions/&amp;lt;plugin&amp;gt;/setup-api.js`, OpenClaw could load and execute that JavaScript during ordinary provider/model status resolution.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This is arbitrary JavaScript execution in the OpenClaw process under the current user account. A malicious repository could run code when the user executed commands such as provider/model inspection from that directory. The issue does not require gateway network exposure, but it does require user interaction: the user must run OpenClaw from a directory containing the attacker-controlled setup file.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw` on npm
- Affected: versions before `2026.4.23`
- Fixed: `2026.4.23`
- Latest stable verified fixed: `openclaw@2026.4.23`, tag `v2026.4.23`&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;OpenClaw now resolves bundled setup fallbacks only from the canonical package/repository root and no longer includes `process.cwd()` as a trusted setup-api search root. A regression test verifies that a workspace-local `extensions/&amp;lt;plugin&amp;gt;/setup-api.js` is not loaded through provider setup resolution.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `993781e6e6eaf50f033cfc3e3bf4f47059740707` (`fix(plugins): ignore cwd setup-api fallback`)&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Severity remains `high` because successful exploitation allows arbitrary code execution under the user ru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r39h-4c2p-3jxp</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1280 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1280</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1280</guid>
    </item>
  </channel>
</rss>
