A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult.
A low-severity authentication weakness exists in the droidclaw project (versions up to 0.5.3) within the claim endpoint at server/src/routes/pairing.ts. The flaw allows improper restriction of excessive authentication attempts, which could facilitate brute-force or credential-stuffing attacks. The attack vector is network-based, but the CVSS attack complexity is rated high and exploitability is described [truncated]