Skip to content

OpenClaw's unauthenticated Nostr profile HTTP endpoints allow remote profile/config tampering

Moderate severity GitHub Reviewed Published Feb 14, 2026 in openclaw/openclaw • Updated Mar 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts