OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.3157700d716f660591fb6e09727f3ca8041fa48b9d — 2026-03-31T19:55:03+09:002026.3.31.Thanks @ccreater222 for reporting.
{
"cwe_ids": [
"CWE-200",
"CWE-312"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-02T20:58:08Z",
"nvd_published_at": "2026-04-28T19:37:41Z",
"severity": "MODERATE"
}