Description
Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated attackers reaching port 18790, which binds all interfaces by default, can inject blind prompts into the user's main OpenClaw agent session as user instructions.
Published: 2026-10-11
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Remote Prompt Injection
Action: Patch Immediately
AI Analysis

Impact

The Nexting pinclaw plugin version 0.3.0 contains a missing authentication check on POST /pinclaw/send. Unauthenticated attackers who can reach the service on port 18790, which listens on all interfaces, can inject blind prompts directly into the primary OpenClaw agent session. If the agent executes these prompts, the attacker effectively gains the ability to command the agent as if it were a regular user, potentially leading to execution of commands that the agent is authorized to perform. The flaw corresponds to CWE‑306, an authentication bypass.

Affected Systems

Affected products include Nexting’s pinclaw OpenClaw channel plugin for version 0.3.0. The plugin is typically deployed on servers that expose port 18790; the listener uses all network interfaces by default. No other vendor or OS details are provided.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, which indicates it is moderate to high severity. EPSS data is not available, so the exact exploitation frequency is unknown, but the bug is unauthenticated and easy to trigger if the port is reachable. The issue is not yet listed in the CISA KEV catalog, which may suggest limited current exploitation activity. Attackers could use this flaw to inject blind prompts without authentication, which would be executed by the agent and could perform actions within the agent's authorized scope.

Generated by OpenCVE AI on October 11, 2026 at 14:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Nexting pinclaw version that restores authentication for POST /pinclaw/send.
  • Restrict the plugin’s listening interface to localhost or a trusted network, or use firewall rules to block external access to port 18790.
  • Configure TLS and require client authentication for the /pinclaw/send endpoint to prevent unauthenticated usage.

Generated by OpenCVE AI on October 11, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated attackers reaching port 18790, which binds all interfaces by default, can inject blind prompts into the user's main OpenClaw agent session as user instructions.
Title Nexting pinclaw through 0.3.0 Missing Authentication via POST /pinclaw/send
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:55.198Z

Reserved: 2026-10-11T01:57:27.711Z

Link: CVE-2026-108757

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:20.840

Modified: 2026-10-11T13:17:20.840

Link: CVE-2026-108757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function