A vulnerability was found in unitedbyai droidclaw up to 0.5.3. It has been classified as critical. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass.
This vulnerability is registered as CVE-2026-17531. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.