<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 01:31:17 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41386 — OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41386</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Bootstrap setup codes were not bound to the intended device role and scopes, allowing first-use privilege escalation during pairing.&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real first-use bootstrap privilege-escalation bug fixed and shipped in v2026.3.22+, so keep open for publication with current severity.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.13-1`
- Patched versions: `&amp;gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a600c72ed7d0045a27f58bf031d2b36ecb0141c9` — 2026-03-22T23:57:15-07:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Bootstrap setup codes were not bound to the intended device role and scopes, allowing first-use privilege escalation during pairing.&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real first-use bootstrap privilege-escalation bug fixed and shipped in v2026.3.22+, so keep open for publication with current severity.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.13-1`
- Patched versions: `&amp;gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a600c72ed7d0045a27f58bf031d2b36ecb0141c9` — 2026-03-22T23:57:15-07:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41386</guid>
    </item>
    <item>
      <title>EUVD-2026-307809</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307809</link>
      <description>EUVD-2026-307809</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307809</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41386</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41386</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41386</guid>
    </item>
    <item>
      <title>GHSA-gg9v-mgcp-v6m7 — OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gg9v-mgcp-v6m7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Bootstrap setup codes were not bound to the intended device role and scopes, allowing first-use privilege escalation during pairing.&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real first-use bootstrap privilege-escalation bug fixed and shipped in v2026.3.22+, so keep open for publication with current severity.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.13-1`
- Patched versions: `&amp;gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a600c72ed7d0045a27f58bf031d2b36ecb0141c9` — 2026-03-22T23:57:15-07:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Bootstrap setup codes were not bound to the intended device role and scopes, allowing first-use privilege escalation during pairing.&lt;/p&gt;
&lt;p&gt;## Current Maintainer Triage
- Status: open
- Normalized severity: high
- Assessment: Real first-use bootstrap privilege-escalation bug fixed and shipped in v2026.3.22+, so keep open for publication with current severity.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `&amp;lt;=2026.3.13-1`
- Patched versions: `&amp;gt;= 2026.3.22`
- First stable tag containing the fix: `v2026.3.22`&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `a600c72ed7d0045a27f58bf031d2b36ecb0141c9` — 2026-03-22T23:57:15-07:00&lt;/p&gt;
&lt;p&gt;OpenClaw thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gg9v-mgcp-v6m7</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0948 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0948</guid>
    </item>
  </channel>
</rss>
