Medium severity6.5NVD Advisory· Published Oct 11, 2026
CVE-2026-108757
CVE-2026-108757
Description
Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated attackers reaching port 18790, which binds all interfaces by default, can inject blind prompts into the user's main OpenClaw agent session as user instructions.
Affected products
2- Package: https://npmjs.com/package/pinclaw
- Range: <=0.3.0
Patches
Vulnerability mechanics
References
5- github.com/Nexting-ai/nexting/blob/a4b75f0429d3b1bf35eef68a296b2e72aa9c7483/plugin/src/core/http-router.tsnvd
- github.com/Nexting-ai/nexting/blob/a4b75f0429d3b1bf35eef68a296b2e72aa9c7483/plugin/src/core/server.tsnvd
- hackmd.io/@haind/nexting-pinclaw-send-unauth-agent-injectionnvd
- www.npmjs.com/package/pinclawnvd
- www.vulncheck.com/advisories/nexting-pinclaw-through-0.3.0-missing-authentication-via-post-pinclaw-sendnvd
News mentions
0No linked articles in our index yet.