
CVE-2026-28450 OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/c… https://www.cve.org/CVERecord?id=CVE-2026-28450
Post summary
The text discloses that OpenClaw versions earlier than 2026.2.12 with the Nostr plugin enabled expose unauthenticated HTTP endpoints.
