<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:14:16 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-53812 — OpenClaw's browser act interactions could bypass private-network navigation checks</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53812</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.&lt;/p&gt;
&lt;p&gt;This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.&lt;/p&gt;
&lt;p&gt;The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.&lt;/p&gt;
&lt;p&gt;This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.&lt;/p&gt;
&lt;p&gt;The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53812</guid>
    </item>
    <item>
      <title>EUVD-2026-329564</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329564</link>
      <description>EUVD-2026-329564</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329564</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53812</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53812</link>
      <description>&lt;p&gt;OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to private-network targets via action-triggered redirects and subsequently read restricted page content using browser evaluation capabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to private-network targets via action-triggered redirects and subsequently read restricted page content using browser evaluation capabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53812</guid>
    </item>
    <item>
      <title>GHSA-2hfg-4fh4-qp7f — OpenClaw's browser act interactions could bypass private-network navigation checks</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2hfg-4fh4-qp7f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.&lt;/p&gt;
&lt;p&gt;This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.&lt;/p&gt;
&lt;p&gt;The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw&amp;#39;s browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.&lt;/p&gt;
&lt;p&gt;This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.&lt;/p&gt;
&lt;p&gt;The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2hfg-4fh4-qp7f</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1738 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</guid>
    </item>
  </channel>
</rss>
