Critical Vulnerability in Clawvet Self-Hosted API Server: CVE-2026-62241
A critical vulnerability (CVE-2026-62241, CVSS 9.1) exists in the Clawvet self-hosted API server (apps/api) before version 0.7.5. The vulnerability allows a remote unauthenticated attacker to harvest user IDs, forge a valid session cookie, and obtain sensitive user information. The vulnerability has not been actively exploited but poses a significant risk due to its severity and the potential for exploitation. Immediate patching to version 0.7.5 or later is strongly recommended.