HIGH
Nexting
CVE published 2026-10-11
CVE-2026-108757
CVE-2026-108757 debrief: Nexting pinclaw through 0.3.0 contains a missing authentication vulnerability in the OpenClaw channel plugin. Unauthenticated attackers can inject blind prompts into the user's main OpenClaw agent session as user instructions. This vulnerability allows attackers to potentially manipulate the OpenClaw agent session, leading to unauthorized actions. Defenders should assess their exp [truncated]