PT-2026-35770 · Openclaw · Openclaw

Ccreater

+2

·

Published

2026-04-02

·

Updated

2026-05-01

·

CVE-2026-41385

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description The software stores the Nostr privateKey as plaintext within the configuration. This allows the exposure of plaintext signing keys used for Nostr protocol operations through calls to the config.get() function, which bypasses redaction mechanisms.
Recommendations Update to version 2026.3.31 or later.

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-41385
GHSA-JJW7-3VJF-FG5J

Affected Products

Openclaw