Executive brief
Claw Orchestrator, a tool used for managing and searching session data, is vulnerable to a denial-of-service attack. An attacker can submit a specially crafted search pattern that causes the server to become unresponsive. This prevents legitimate users from accessing the service and can halt operations until the server is restarted or the process recovers.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `validateRegex` function within `src/embedded-server.ts`. The `/session/grep` endpoint accepts user-provided regex patterns via the `body.pattern` argument without sufficient complexity validation. Because the application runs on Node.js, a malicious pattern triggering catastrophic backtracking can block the single-threaded event loop. This results in a complete hang of the server, impacting availability for all users. The issue is fixed in version 3.7.1 by improving regex validation and handling.
Affected products
- Enderfga claw-orchestrator <= 3.7.0
Timeline
- 2026-05-11: disclosed: Issue reported on GitHub
- 2026-06-01: advisory: NVD Published Date
- 2026-06-02: patched: GitHub Advisory published and patch confirmed in 3.7.1
References
- https://github.com/Enderfga/claw-orchestrator/issues/64
- https://github.com/Enderfga/claw-orchestrator/issues/64
- https://github.com/Enderfga/claw-orchestrator/commit/3f970a974c65a94555c25af9f2796f11315e4584
- https://github.com/Enderfga/claw-orchestrator
- https://github.com/Enderfga/claw-orchestrator/releases/tag/v3.7.1