Sceawere
Vulnerability Detail
CVE-2026-108757UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authentication in Pinclaw Plugin
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- Nexting
- Product
- pinclaw
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated attackers reaching port 18790, which binds all interfaces by default, can inject blind prompts into the user's main OpenClaw agent session as user instructions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-11T13:17:20.840Z",
"pubdate": "2026-10-11T13:17:20.840Z",
"executiveSummary": "The Pinclaw OpenClaw channel plugin, versions through 0.3.0, contains a critical missing authentication vulnerability within its HTTP routing logic.\nThis vulnerability stems from a failure to enforce authentication checks on the POST /pinclaw/send endpoint, allowing unauthenticated remote attackers to interact with the service.\nThe flaw affects systems running the OpenClaw agent, particularly because the service defaults to binding to all network interfaces on port 18790, exposing the internal API to external network segments.\nSuccessful exploitation permits an attacker to inject arbitrary blind prompts into the primary OpenClaw agent session, effectively hijacking the agent's instruction stream.\nAs the injected prompts are executed as user instructions, the attacker can manipulate the agent's behavior, potentially leading to unauthorized data access, command execution, or session manipulation.\nThis vulnerability represents a significant security risk due to the lack of access controls and the ease of network reachability, requiring immediate attention to prevent unauthorized remote control of the OpenClaw environment.",
"technicalDetails": "The vulnerability is located in the src/core/http-router.ts file of the Pinclaw OpenClaw channel plugin. The root cause is an improper implementation of access control mechanisms within the HTTP request processing pipeline for the /pinclaw/send endpoint.\nAnalysis of the source code reveals that the routine responsible for validating the authToken is explicitly bypassed during the handling of POST requests directed at this specific path. Consequently, the application assumes that requests arriving at this endpoint do not require valid session credentials, effectively disabling security checks for the primary interface used to inject agent prompts.\nThe attack flow begins with an unauthenticated attacker identifying the target service running on port 18790. Because the plugin binds to all network interfaces (0.0.0.0) by default, the service is often exposed to both internal and external network traffic unless strictly segmented by upstream firewalls.\nAn attacker can exploit this by crafting a malicious HTTP POST request targeting /pinclaw/send. Since the authToken check is absent, the backend server processes the payload without verifying the requester's identity. The payload, which contains arbitrary prompt data, is then treated by the OpenClaw architecture as legitimate user input.\nOnce the injected payload reaches the OpenClaw agent, it is parsed and executed as a valid system instruction. This results in 'blind' prompt injection, where the agent processes attacker-supplied commands within its authorized session context. The attacker does not require prior knowledge of the user's session tokens or elevated privileges to initiate this attack.\nThe impact of this post-exploitation scenario is severe. The attacker can force the agent to perform actions on behalf of the legitimate user, which may include exfiltrating information, modifying agent configurations, or interacting with integrated systems, depending on the permissions and capabilities granted to the OpenClaw agent instance. The failure to validate incoming requests at the application layer completely undermines the authentication model intended for the OpenClaw ecosystem."
}