2026.1.24-3
1 months ago
17 days ago
Known vulnerabilities in the clawdbot package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
clawdbot is a WhatsApp gateway CLI (Baileys web) with Pi RPC agent Affected versions of this package are vulnerable to Command Injection via unsafe handling of the Note: This is only exploitable if Docker sandbox mode is enabled. How to fix Command Injection? A fix was pushed into the | * |
clawdbot is a WhatsApp gateway CLI (Baileys web) with Pi RPC agent Affected versions of this package are vulnerable to Credential Exposure in the form of gateway query parameter hook tokens being sent in websocket responses. An attacker who convinces a user to follow a link with a malicious Note: Instances configured to listen on loopback only are also vulnerable, because the victim's browser initiates the outbound connection. How to fix Credential Exposure? A fix was pushed into the | * |