Description
A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Recommendation
Update the @enderfga/claw-orchestrator package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.5.5
- Patched version(s): 3.5.6
References
Could your website be exposed too?
SmartScanner can check your website for Claw Orchestrator is missing authentication for the component API Endpoint and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Claw Orchestrator has inefficient regular expression complexity via validateRegex() - CVE-2026-10291
- @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default - CVE-2026-54504
- @delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck - CVE-2026-39397
- Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Ex - CVE-2026-45395


