<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 08:07:16 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41378 — OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41378</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Paired node escalates to gateway RCE via unrestricted node.event agent dispatch&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: high
- Assessment: v2026.3.28 still lets paired role=node clients drive node.event agent.request into broader gateway-side tool access than node RPCs, but critical is overstated because a trusted paired node foothold is already required.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a77928b1087e90f2a8903f8e5aca6dec9237ac62` — 2026-03-30T14:22:15+01:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Paired node escalates to gateway RCE via unrestricted node.event agent dispatch&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: high
- Assessment: v2026.3.28 still lets paired role=node clients drive node.event agent.request into broader gateway-side tool access than node RPCs, but critical is overstated because a trusted paired node foothold is already required.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a77928b1087e90f2a8903f8e5aca6dec9237ac62` — 2026-03-30T14:22:15+01:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41378</guid>
    </item>
    <item>
      <title>EUVD-2026-307915</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307915</link>
      <description>EUVD-2026-307915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307915</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41378</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41378</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41378</guid>
    </item>
    <item>
      <title>GHSA-gjm7-hw8f-73rq — OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gjm7-hw8f-73rq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Paired node escalates to gateway RCE via unrestricted node.event agent dispatch&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: high
- Assessment: v2026.3.28 still lets paired role=node clients drive node.event agent.request into broader gateway-side tool access than node RPCs, but critical is overstated because a trusted paired node foothold is already required.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a77928b1087e90f2a8903f8e5aca6dec9237ac62` — 2026-03-30T14:22:15+01:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Paired node escalates to gateway RCE via unrestricted node.event agent dispatch&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: narrow
- Normalized severity: high
- Assessment: v2026.3.28 still lets paired role=node clients drive node.event agent.request into broader gateway-side tool access than node RPCs, but critical is overstated because a trusted paired node foothold is already required.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.28`
- Patched versions: `&amp;gt;= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a77928b1087e90f2a8903f8e5aca6dec9237ac62` — 2026-03-30T14:22:15+01:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @AntAISecurityLab for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gjm7-hw8f-73rq</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</guid>
    </item>
  </channel>
</rss>
