<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Imessage — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/imessage/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 31 Mar 2026 12:16:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/imessage/feed.xml" rel="self" type="application/rss+xml"/><item><title>OpenClaw Remote Command Injection via iMessage Attachment Staging (CVE-2026-32917)</title><link>https://feed.craftedsignal.io/briefs/2026-03-openclaw-rce/</link><pubDate>Tue, 31 Mar 2026 12:16:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-openclaw-rce/</guid><description>OpenClaw before 2026.3.13 is vulnerable to remote command injection via unsanitized iMessage attachment paths passed to the SCP remote operand, allowing attackers to execute arbitrary commands on configured remote hosts when remote attachment staging is enabled.</description><content:encoded>&lt;p>OpenClaw, a software application whose specific function is not detailed in the provided context, is vulnerable to a remote command injection flaw. Specifically, versions prior to 2026.3.13 are susceptible. This vulnerability, identified as CVE-2026-32917, resides within the iMessage attachment staging process.  Attackers can exploit this flaw by injecting shell metacharacters into unsanitized remote attachment paths. This occurs because these paths are directly passed to the SCP command…&lt;/p>
</content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>command-injection</category><category>imessage</category><category>openclaw</category></item></channel></rss>