Claw Orchestrator is missing authentication for the component API Endpoint
- Severity:
- Medium
Description
A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Recommendation
Update the @enderfga/claw-orchestrator package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.5.5
- Patched version(s): 3.5.6
References
Related Issues
- Claw Orchestrator has inefficient regular expression complexity via validateRegex() - CVE-2026-10291
- @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default - CVE-2026-54504
- @delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck - CVE-2026-39397
- Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Ex - CVE-2026-45395
You might also like:
- Tags:
- npm
- @enderfga/claw-orchestrator
Anything's wrong? Let us know Last updated on July 09, 2026


