<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:12:34 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-41353 — OpenClaw &lt; 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-41353</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OpenClaw&lt;/p&gt;
&lt;p&gt;OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OpenClaw&lt;/p&gt;
&lt;p&gt;OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-41353</guid>
    </item>
    <item>
      <title>GHSA-h5hg-h7rr-gpf3 — OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h5hg-h7rr-gpf3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real released allowProfiles bypass through profile mutation and runtime profile selection, fixed and shipped in v2026.3.22+, so keep open for publish rather than close.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.13-1`
- Patched versions: `&amp;gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `eac93507c36ccd0c359fba18fa466ef6448be8a5` — 2026-03-23T00:56:44-07:00&lt;/p&gt;
&lt;p&gt;## Release Process Note
- The fix is already present in released version `2026.3.22`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.&lt;/p&gt;
&lt;p&gt;Thanks @smaeljaish771 for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real released allowProfiles bypass through profile mutation and runtime profile selection, fixed and shipped in v2026.3.22+, so keep open for publish rather than close.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.13-1`
- Patched versions: `&amp;gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `eac93507c36ccd0c359fba18fa466ef6448be8a5` — 2026-03-23T00:56:44-07:00&lt;/p&gt;
&lt;p&gt;## Release Process Note
- The fix is already present in released version `2026.3.22`.
- This draft looks ready for final maintainer disposition or publication, not additional code-fix work.&lt;/p&gt;
&lt;p&gt;Thanks @smaeljaish771 for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h5hg-h7rr-gpf3</guid>
    </item>
  </channel>
</rss>
