logo

Lock the Front Door: The “Localhost” Loophole Leaving Thousands of Clawdbot Agents Exposed

ID: e9fa65c8-4318-548f-82bb-32403fe2d474

STIX ID: report--e9fa65c8-4318-548f-82bb-32403fe2d474

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

Clawdbot instances deployed with default local-development settings can be trivially exposed when placed behind reverse proxies (NGINX/Caddy) that rewrite client IPs to 127.0.0.1, allowing external requests to bypass authentication and enabling attackers to execute commands and exfiltrate sensitive telemetry and credentials; researchers found ~1,000 publicly reachable instances with at least ~300 unauthenticated, and maintainers have issued configuration fixes and documentation updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.