<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:08:06 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-35637 — OpenClaw &lt; 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-35637</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OpenClaw&lt;/p&gt;
&lt;p&gt;OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or manipulate content before proper authorization validation occurs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OpenClaw&lt;/p&gt;
&lt;p&gt;OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or manipulate content before proper authorization validation occurs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-35637</guid>
    </item>
    <item>
      <title>GHSA-vfg3-pqpq-93m4 — OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vfg3-pqpq-93m4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Tlon cite expansion happened before channel and DM authorization completed, allowing cite work and content handling before the final auth decision.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `3cbf932413e41d1836cb91aed1541a28a3122f93`
- `ebee4e2210e1f282a982c7ef2ad79d77a572fc87`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/tlon/src/monitor/index.ts now defers cite expansion until after authorization and preserves explicit empty-allowlist semantics.
- extensions/tlon/src/monitor/utils.ts and extensions/tlon/src/security.test.ts ship the deferred cite expansion behavior and regressions.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @zpbrent for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Tlon cite expansion happened before channel and DM authorization completed, allowing cite work and content handling before the final auth decision.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: &amp;lt; 2026.3.22
- Fixed: &amp;gt;= 2026.3.22
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `3cbf932413e41d1836cb91aed1541a28a3122f93`
- `ebee4e2210e1f282a982c7ef2ad79d77a572fc87`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix shipped in `v2026.3.22` and remains present in `v2026.3.23` and `v2026.3.23-2`.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- extensions/tlon/src/monitor/index.ts now defers cite expansion until after authorization and preserves explicit empty-allowlist semantics.
- extensions/tlon/src/monitor/utils.ts and extensions/tlon/src/security.test.ts ship the deferred cite expansion behavior and regressions.&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @zpbrent for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vfg3-pqpq-93m4</guid>
    </item>
  </channel>
</rss>
