What happened
VulnCheck published CVE-2026-108757 (published 2026-10-11, CVSS 6.5 v3.1 / 7.1 v4.0, CWE-306) for the Nexting pinclaw OpenClaw channel plugin ≤ 0.3.0: the auth token check is skipped on POST /pinclaw/send and the server binds all interfaces by default, allowing unauthenticated blind prompt injection into the main agent. Verified against NVD REST API.
Why it matters
This is an agent-takeover primitive: by injecting instructions into the main OpenClaw agent session, an attacker can steer an autonomous agent to take destructive actions, exfiltrate data or pivot into connected tooling — the exact prompt-injection-to-agent-execution class defenders must block, and it is unauthenticated over the network.
Attack vector
Unauthenticated attacker reaching port 18790 sends a crafted POST /pinclaw/send; src/core/http-router.ts skips the authToken check (CWE-306) on that route, injecting blind prompts into the user's main OpenClaw agent session as user instructions.
Affected systems
Nexting pinclaw OpenClaw channel plugin (npm: pinclaw) through 0.3.0
Mitigation
Upgrade past 0.3.0 or ensure the pinclaw HTTP service binds to loopback only and the authToken is enforced; place it behind authentication. Advisory: https://www.vulncheck.com/advisories/nexting-pinclaw-through-0.3.0-missing-authentication-via-post-pinclaw-send