<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:22:39 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-43574 — OpenClaw &lt; 2026.4.12 - Improper Authorization via Empty Approver Lists</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-43574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OpenClaw&lt;/p&gt;
&lt;p&gt;OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OpenClaw&lt;/p&gt;
&lt;p&gt;OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-43574</guid>
    </item>
    <item>
      <title>GHSA-49cg-279w-m73x — OpenClaw: Empty approver lists could grant explicit approval authorization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-49cg-279w-m73x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Empty approver lists could grant explicit approval authorization.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.12`
- Patched versions: `&amp;gt;= 2026.4.12`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @anshumanbh for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Empty approver lists could grant explicit approval authorization.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions&lt;/p&gt;
&lt;p&gt;- Package: `openclaw`
- Ecosystem: npm
- Affected versions: `&amp;lt; 2026.4.12`
- Patched versions: `&amp;gt;= 2026.4.12`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;For helper-backed channels, an empty resolved approver list could be interpreted as explicit approval authorization, allowing a sender outside the normal channel authorization gate to resolve pending approvals if they knew an approval id.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The fix prevents empty approver lists from granting explicit approval authorization and adds regression coverage for unauthorized senders.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;The issue was fixed in #65714. The first stable tag containing the fix is `v2026.4.12`, and `openclaw@2026.4.14` includes the fix.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)&lt;/p&gt;
&lt;p&gt;- `0a105c0900de701d2ee9f1abc96b017afbd0afdd`
- PR: #65714&lt;/p&gt;
&lt;p&gt;## Release Process Note&lt;/p&gt;
&lt;p&gt;Users should upgrade to `openclaw` 2026.4.12 or newer. The latest npm release, `2026.4.14`, already includes the fix.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Thanks to @anshumanbh for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-49cg-279w-m73x</guid>
    </item>
  </channel>
</rss>
