Junglewise Threat Intelligence

CVE-2026-41301: OpenClaw: Forged Nostr DMs could create pairing state before signature verification

CVE-2026-41301 · Severity: medium · CVSS 5.3 · Published 2026-04-07

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Nostr client library used to handle encrypted direct messages. The vulnerability allows an unauthenticated attacker to forge Nostr direct messages and trigger pairing state creation before the message signature is validated, potentially exhausting pairing capacity and forcing unnecessary relay/logging operations. The vulnerability does not enable message decryption, unauthorized pairing approval, or broader system compromise.

Technical details

The vulnerability is a signature verification bypass (CWE-347) in the Nostr DM ingress path. Before version 2026.3.31, the code issued pairing challenges and created pending pairing entries before validating the event signature, allowing an unauthenticated remote sender to craft forged DMs that trigger pairing-reply operations. An attacker can consume shared pairing capacity and cause bounded relay/logging work without authentication or user interaction. The fix, shipped in version 2026.3.31 on March 31, 2026, verifies inbound DM signatures before initiating pairing replies.

Affected products

  • OpenClaw openclaw >= 2026.3.22, < 2026.3.31

Timeline

  • 2026-04-07: disclosed: Published on GitHub Advisory Database
  • 2026-03-31: patched: Fix shipped in version 2026.3.31

References

Related threats