Vulnerability library
Security checkJuly 09, 2026

Claw Orchestrator has inefficient regular expression complexity via validateRegex()

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The manipulation of the argument body.pattern leads to inefficient regular expression complexity.

Recommendation

Update the @enderfga/claw-orchestrator package to the latest compatible version. Followings are version details:

  • Affected version(s): < 3.7.1
  • Patched version(s): 3.7.1

References

Could your website be exposed too?

SmartScanner can check your website for Claw Orchestrator has inefficient regular expression complexity via validateRegex() and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 09, 2026