CVE-2026-41385

Severity CVSS v4.0:
HIGH
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
28/04/2026
Last modified:
01/05/2026

Description

OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext signing keys used for Nostr protocol operations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* 2026.3.31 (excluding)