CVE-2026-10281
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Description
A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.5.6 mitigates this issue. Patch name: d0b02a800aa0689d9428cc4cc170e0b6589fb2c3. The affected component should be upgraded.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-287
Source
NVD
Vendor
Enderfga
Product
claw-orchestrator
External References
- https://github.com/Enderfga/claw-orchestrator/
- https://github.com/Enderfga/claw-orchestrator/commit/d0b02a800aa0689d9428cc4cc170e0b6589fb2c3
- https://github.com/Enderfga/claw-orchestrator/issues/61
- https://github.com/Enderfga/claw-orchestrator/releases/tag/v3.5.6
- https://vuldb.com/cve/CVE-2026-10281
- https://vuldb.com/submit/825429
- https://vuldb.com/vuln/367574
- https://vuldb.com/vuln/367574/cti
Discussion (0)
Add Comment
No comments yet. Be the first!