<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:05:46 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-53816 — OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53816</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw nodes send lifecycle events back to the gateway. In affected releases, a paired node could send an exec lifecycle event that was accepted without enough provenance tying it to an authorized `system.run` request.&lt;/p&gt;
&lt;p&gt;This issue affects the node event boundary. It does not allow an unauthenticated caller to reach the gateway; the attacker must already control a paired node connection.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments with a paired node where that node can send crafted `node.event` messages to the gateway and the target agent/session can process exec lifecycle events.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A malicious or compromised paired node could make the gateway treat attacker-supplied event data as an exec lifecycle result. In the vulnerable flow, that could steer the target session into an exec-event path that exposed capabilities the reduced node surface should not have provided.&lt;/p&gt;
&lt;p&gt;The issue is a missing provenance check for node-originated lifecycle events.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Pair nodes only from trusted environments, and remove/re-pair nodes that may have been compromised.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw nodes send lifecycle events back to the gateway. In affected releases, a paired node could send an exec lifecycle event that was accepted without enough provenance tying it to an authorized `system.run` request.&lt;/p&gt;
&lt;p&gt;This issue affects the node event boundary. It does not allow an unauthenticated caller to reach the gateway; the attacker must already control a paired node connection.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments with a paired node where that node can send crafted `node.event` messages to the gateway and the target agent/session can process exec lifecycle events.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A malicious or compromised paired node could make the gateway treat attacker-supplied event data as an exec lifecycle result. In the vulnerable flow, that could steer the target session into an exec-event path that exposed capabilities the reduced node surface should not have provided.&lt;/p&gt;
&lt;p&gt;The issue is a missing provenance check for node-originated lifecycle events.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Pair nodes only from trusted environments, and remove/re-pair nodes that may have been compromised.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-53816</guid>
    </item>
    <item>
      <title>EUVD-2026-329568</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329568</link>
      <description>EUVD-2026-329568</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329568</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53816</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53816</link>
      <description>&lt;p&gt;OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering target sessions into exec-event paths that expose capabilities the reduced node surface should not provide.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering target sessions into exec-event paths that expose capabilities the reduced node surface should not provide.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53816</guid>
    </item>
    <item>
      <title>GHSA-3c6j-hq33-3jv4 — OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3c6j-hq33-3jv4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw nodes send lifecycle events back to the gateway. In affected releases, a paired node could send an exec lifecycle event that was accepted without enough provenance tying it to an authorized `system.run` request.&lt;/p&gt;
&lt;p&gt;This issue affects the node event boundary. It does not allow an unauthenticated caller to reach the gateway; the attacker must already control a paired node connection.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments with a paired node where that node can send crafted `node.event` messages to the gateway and the target agent/session can process exec lifecycle events.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A malicious or compromised paired node could make the gateway treat attacker-supplied event data as an exec lifecycle result. In the vulnerable flow, that could steer the target session into an exec-event path that exposed capabilities the reduced node surface should not have provided.&lt;/p&gt;
&lt;p&gt;The issue is a missing provenance check for node-originated lifecycle events.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Pair nodes only from trusted environments, and remove/re-pair nodes that may have been compromised.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OpenClaw nodes send lifecycle events back to the gateway. In affected releases, a paired node could send an exec lifecycle event that was accepted without enough provenance tying it to an authorized `system.run` request.&lt;/p&gt;
&lt;p&gt;This issue affects the node event boundary. It does not allow an unauthenticated caller to reach the gateway; the attacker must already control a paired node connection.&lt;/p&gt;
&lt;p&gt;### Affected configurations&lt;/p&gt;
&lt;p&gt;This affects deployments with a paired node where that node can send crafted `node.event` messages to the gateway and the target agent/session can process exec lifecycle events.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A malicious or compromised paired node could make the gateway treat attacker-supplied event data as an exec lifecycle result. In the vulnerable flow, that could steer the target session into an exec-event path that exposed capabilities the reduced node surface should not have provided.&lt;/p&gt;
&lt;p&gt;The issue is a missing provenance check for node-originated lifecycle events.&lt;/p&gt;
&lt;p&gt;### Patched Versions&lt;/p&gt;
&lt;p&gt;The first stable patched version is `2026.5.18`.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Upgrade to `openclaw@2026.5.18` or later. Pair nodes only from trusted environments, and remove/re-pair nodes that may have been compromised.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3c6j-hq33-3jv4</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1738 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Sicherheitsmechanismen zu umgehen, erhöhte Berechtigungen zu erlangen, Informationen offenzulegen, Konfigurationen zu manipulieren, beliebige Befehle oder Code auszuführen sowie interne Systeme über SSRF anzugreifen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1738</guid>
    </item>
  </channel>
</rss>
