Junglewise Threat Intelligence

Schubydoo Clauster missing authentication in dashboard and API

Severity: high · CVSS 8.7 · Published 2026-07-10

Vendors: PyPI.

Executive brief

Clauster, a tool for managing Claude Code remote-control bridges, contains a flaw where the dashboard and API may be accessible without a password even if one is configured. This occurs when the software is set to listen on a network address but a specific 'enabled' flag is missing from the configuration. An attacker with network access can gain full control over the dashboard, allowing them to execute code within project directories and access sensitive logs.

Technical details

Clauster (<= 0.2.1) fails to enforce authentication on non-loopback deployments (e.g., 0.0.0.0) if the 'auth.enabled' configuration key is not explicitly set to true, even if 'auth.password_required' is enabled. This is caused by a discrepancy between the config validator, which allowed the service to start without 'auth.enabled' being set, and the runtime auth guard, which only enforces checks if that specific flag is true. An unauthenticated attacker with network access can interact with the API to spawn or stop bridges, which effectively allows remote code execution (RCE) in project directories. The vulnerability is patched in version 0.2.2 by making the configuration validator 'fail closed' for network-bound instances.

Affected products

  • schubydoo clauster <= 0.2.1
  • schubydoo ghcr.io/schubydoo/clauster (Docker image) <= 0.2.1

Timeline

  • 2026-06-03: disclosed: Initial disclosure by maintainer
  • 2026-07-10: advisory: GitHub Advisory published
  • 2026-07-10: patched: Version 0.2.2 released

References