Missing Authentication Flaw in Nexting Pinclaw OpenClaw Channel Plugin
CVE-2026-108757
7.1HIGH
What is CVE-2026-108757?
The Nexting Pinclaw OpenClaw channel plugin version 0.3.0 has a significant missing authentication vulnerability. Specifically, this flaw resides in src/core/http-router.ts where the authToken check is bypassed on the POST request to /pinclaw/send. As a result, unauthenticated attackers can access port 18790—defaulting to all interfaces—allowing them to inject blind prompts directly into the main OpenClaw agent session. This could lead to manipulation of user instructions, highlighting the critical need for authentication checks in API endpoints.
Affected Version(s)
pinclaw 0 <= 0.3.0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
