Impact
The Nexting pinclaw plugin version 0.3.0 contains a missing authentication check on POST /pinclaw/send. Unauthenticated attackers who can reach the service on port 18790, which listens on all interfaces, can inject blind prompts directly into the primary OpenClaw agent session. If the agent executes these prompts, the attacker effectively gains the ability to command the agent as if it were a regular user, potentially leading to execution of commands that the agent is authorized to perform. The flaw corresponds to CWE‑306, an authentication bypass.
Affected Systems
Affected products include Nexting’s pinclaw OpenClaw channel plugin for version 0.3.0. The plugin is typically deployed on servers that expose port 18790; the listener uses all network interfaces by default. No other vendor or OS details are provided.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, which indicates it is moderate to high severity. EPSS data is not available, so the exact exploitation frequency is unknown, but the bug is unauthenticated and easy to trigger if the port is reachable. The issue is not yet listed in the CISA KEV catalog, which may suggest limited current exploitation activity. Attackers could use this flaw to inject blind prompts without authentication, which would be executed by the agent and could perform actions within the agent's authorized scope.
OpenCVE Enrichment