Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-62241

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known secret, and call GET /api/v1/auth/me to obtain the victim's email address, subscription plan, and secret apiKey. The published clawvet npm package (CLI only) is not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.065
EPSS Ranking 93.2%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-62241


Contact Us

Shodan ® - All rights reserved