OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108757 (CVSS 7.1)

NVD · officialPublished Oct 11, 2026Risk 23/100

Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated attackers reaching port 18790, which binds all interfaces by default, can inject blind prompts into the user's main OpenClaw agent session as user instructions.

CVSS
7.1
AV:AdjacentAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source