GHSA-jjw7-3vjf-fg5j

Suggest an improvement
Source
https://github.com/advisories/GHSA-jjw7-3vjf-fg5j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jjw7-3vjf-fg5j/GHSA-jjw7-3vjf-fg5j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jjw7-3vjf-fg5j
Aliases
Downstream
Published
2026-04-02T20:58:08Z
Modified
2026-05-06T02:51:10Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
Details

Summary

OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get

Current Maintainer Triage

  • Status: open
  • Normalized severity: medium
  • Assessment: v2026.3.28 still models Nostr privateKey as plain string so config views can expose it, and the secret-schema fix is unreleased.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.3.31
  • Vulnerable version range: <=2026.3.28
  • Patched versions: >= 2026.3.31
  • First stable tag containing the fix: v2026.3.31

Fix Commit(s)

  • 57700d716f660591fb6e09727f3ca8041fa48b9d — 2026-03-31T19:55:03+09:00

Release Process Note

  • The fix is already present in released version 2026.3.31.
  • This draft looks ready for final maintainer disposition or publication, not additional code-fix work.

Thanks @ccreater222 for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-312"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-02T20:58:08Z",
    "nvd_published_at":  "2026-04-28T19:37:41Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.3.31

Database specific

last_known_affected_version_range
"<= 2026.3.28"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jjw7-3vjf-fg5j/GHSA-jjw7-3vjf-fg5j.json"