Claw Orchestrator has inefficient regular expression complexity via validateRegex()
- Severity:
- Medium
Description
A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The manipulation of the argument body.pattern leads to inefficient regular expression complexity.
Recommendation
Update the @enderfga/claw-orchestrator package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.7.1
- Patched version(s): 3.7.1
References
Related Issues
- steal Inefficient Regular Expression Complexity vulnerability via string variable - CVE-2022-37259
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867
- Luxon Inefficient Regular Expression Complexity vulnerability - CVE-2023-22467
- Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection - CVE-2026-44496
You might also like:
- Tags:
- npm
- @enderfga/claw-orchestrator
Anything's wrong? Let us know Last updated on July 09, 2026


