Vulnerability  ·  2026-10-12

Nexting pinclaw OpenClaw plugin: missing auth on /pinclaw/send → unauthenticated blind prompt injection into the main agent (CVSS 6.5)

VulnerabilityMedium impactGlobalCVE-2026-108757
VulnCheck published CVE-2026-108757 (published 2026-10-11, CVSS 6.5 v3.1 / 7.1 v4.0, CWE-306) for the Nexting pinclaw OpenClaw channel plugin ≤ 0.3.0: the auth token check is skipped on POST /pinclaw/send and the server binds all interfaces by default, allowing unauthenticated blind prompt injection into the main agent. Verified against NVD REST API.
This is an agent-takeover primitive: by injecting instructions into the main OpenClaw agent session, an attacker can steer an autonomous agent to take destructive actions, exfiltrate data or pivot into connected tooling — the exact prompt-injection-to-agent-execution class defenders must block, and it is unauthenticated over the network.
Unauthenticated attacker reaching port 18790 sends a crafted POST /pinclaw/send; src/core/http-router.ts skips the authToken check (CWE-306) on that route, injecting blind prompts into the user's main OpenClaw agent session as user instructions.
Nexting pinclaw OpenClaw channel plugin (npm: pinclaw) through 0.3.0
Upgrade past 0.3.0 or ensure the pinclaw HTTP service binds to loopback only and the authToken is enforced; place it behind authentication. Advisory: https://www.vulncheck.com/advisories/nexting-pinclaw-through-0.3.0-missing-authentication-via-post-pinclaw-send
NVD CVE-2026-108757VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →