Openclaw cli: OpenClaw: Nostr profile mutation routes allowed operator.write config persistence (CVE-2026-43579)
Description
A vulnerability in the Openclaw CLI Nostr plugin allowed profile mutation routes to persist profile configuration without requiring admin authority. This issue affects versions prior to 2026.4.10 and was fixed by enforcing the operator.admin scope for these routes. Users should upgrade to version 2026.4.10 or later to mitigate this vulnerability.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Openclaw CLI Nostr plugin had a security flaw where HTTP profile mutation routes could persist profile configuration without requiring operator.admin privileges. This allowed unauthorized profile configuration changes via the operator.write scope. The vulnerability affects openclaw versions before 2026.4.10. The fix, introduced in pull request #63553 and commit 6517c700de9bb0ee11b41ab625ef3b63d01b6083, requires operator.admin scope for profile mutation routes, preventing unauthorized persistence of profile configurations.
Potential Impact
Unauthorized users with operator.write scope could persist changes to Nostr profile configurations, potentially leading to unauthorized profile modifications. The vulnerability does not require admin privileges, increasing the risk of unauthorized configuration persistence.
Mitigation Recommendations
Upgrade openclaw to version 2026.4.10 or later. The fix is included starting from 2026.4.10, with the latest npm release 2026.4.14 containing the patch. No additional mitigation is required once updated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-43579
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac2459412601ec6a3165c94
Added to database: 10/04/2026, 12:24:52 UTC
Last enriched: 10/04/2026, 12:41:06 UTC
Last updated: 10/04/2026, 16:08:38 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.