CVE-2026-17531 | unitedbyai droidclaw up to 0.5.3 Unsigned Scheduled Callback goals.ts authorization (Issue 18)
A vulnerability was found in unitedbyai droidclaw up to 0.5.3. It has been classified as critical. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass.
This vulnerability is registered as CVE-2026-17531. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More