Vulnerability library
Security checkJuly 09, 2026

Claw Orchestrator is missing authentication for the component API Endpoint

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Recommendation

Update the @enderfga/claw-orchestrator package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 3.5.5
  • Patched version(s): 3.5.6

References

Could your website be exposed too?

SmartScanner can check your website for Claw Orchestrator is missing authentication for the component API Endpoint and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 09, 2026