#VU125180 Incorrect authorization in OpenClaw

 

#VU125180 Incorrect authorization in OpenClaw

Published: April 8, 2026


Vulnerability identifier: #VU125180
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OpenClaw
Software vendor:
OpenClaw

Description

The vulnerability allows a remote attacker to trigger unauthorized computational work.

The vulnerability exists due to incorrect authorization in Nostr inbound DM handling when processing inbound direct messages. A remote attacker can send unauthorized direct messages to trigger unauthorized computational work.

The issue occurs because cryptographic and dispatch work is performed before sender and pairing policy enforcement.


Remediation

Install security update from vendor's website.

External links