Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable
ID: 67f85720-c577-5be1-b6b7-ae0414b692b7
STIX ID: report--67f85720-c577-5be1-b6b7-ae0414b692b7
Feed Name: cybersecurityNews.com
Clawdbot, an open-source AI assistant gateway, has over 900 publicly exposed instances due to a localhost auto-approval/authentication misconfiguration that is bypassed when services are fronted by reverse proxies; unsecured Control UIs and Gateways can expose Anthropic API keys, messaging tokens, months of chat history and permit remote command/tool execution, including root-level commands on some deployments — researchers disclosed findings and recommended proxy hardening, trusted proxy configuration, rotating secrets, and using tunneled access rather than direct public binds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
