#VU125180 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to trigger unauthorized computational work.
The vulnerability exists due to incorrect authorization in Nostr inbound DM handling when processing inbound direct messages. A remote attacker can send unauthorized direct messages to trigger unauthorized computational work.
The issue occurs because cryptographic and dispatch work is performed before sender and pairing policy enforcement.