OpenClaw: Nostr profile mutation routes allowed operator.write config persistence
Moderate severity
GitHub Reviewed
Published
Apr 16, 2026
in
openclaw/openclaw
•
Updated Apr 17, 2026
Description
Published to the GitHub Advisory Database
Apr 17, 2026
Reviewed
Apr 17, 2026
Last updated
Apr 17, 2026
Summary
Nostr profile mutation routes allowed operator.write config persistence.
Affected Packages / Versions
openclaw< 2026.4.10>= 2026.4.10Impact
Nostr plugin HTTP profile routes could persist profile config through a path that did not require admin authority.
Technical Details
The fix requires
operator.adminscope for Nostr profile mutation routes.Fix
The issue was fixed in #63553. The first stable tag containing the fix is
v2026.4.10, andopenclaw@2026.4.14includes the fix.Fix Commit(s)
6517c700de9bb0ee11b41ab625ef3b63d01b6083Release Process Note
Users should upgrade to
openclaw2026.4.10 or newer. The latest npm release,2026.4.14, already includes the fix.Credits
Thanks to @zpbrent and @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.
References