
CVE-2026-41385 OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. A… https://www.cve.org/CVERecord?id=CVE-2026-41385
Post summary
The CVE discloses that OpenClaw versions prior to 2026.3.31 store Nostr private keys in plain text, allowing these credentials to be accessed via config.get calls that bypass its redaction mechanisms.
