CVE-2026-28450 | OpenClaw up to 2026.2.11 Nostr Plugin /api/channels/nostr/ missing authentication (GHSA-mv9j-6xhh-g383)
A vulnerability described as critical has been identified in OpenClaw up to 2026.2.11. This affects an unknown function of the file /api/channels/nostr/ of the component Nostr Plugin. The manipulation results in missing authentication.
This vulnerability was named CVE-2026-28450. The attack needs to be approached locally. There is no available exploit.
Upgrading the affected component is recommended.