Security researchers reported that Clawdbot, an open-source AI agent gateway used to connect LLMs to messaging platforms and local tool execution, is being deployed insecurely at scale, with 900+ internet-exposed instances discovered via Shodan/Censys-style fingerprinting (e.g., the Control UI title Clawdbot Control) and scans of the default service port 18789. Many exposed deployments were unauthenticated, allowing access to the web-based Control UI and WebSocket interfaces, and in some cases exposing configuration data, third-party tokens (e.g., Telegram/Slack), Anthropic API keys, and months of private chat history.
The primary root cause described is an authentication trust flaw combined with common reverse-proxy deployments: Clawdbot’s “localhost auto-approval” logic (intended for local development) can be bypassed when a reverse proxy forwards requests in a way that makes the gateway see the connection as originating from 127.0.0.1, especially when gateway.trustedProxies is not configured to correctly interpret X-Forwarded-For. Both reporting and analysis emphasize that Clawdbot is not a simple app but long-running infrastructure that can hold high-value secrets and execute tools/commands, meaning exposed gateways materially expand organizational attack surface and can enable credential theft and potential remote code execution if attackers can reach tool execution paths in real deployments.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
By 2026-01-26 and 2026-01-27, multiple reports stated that exposed Clawdbot gateways were leaking configuration data, private conversations, API keys, and service tokens, and that some deployments could allow arbitrary command execution or remote code execution when overprivileged.
Clawdbot documentation was updated to emphasize stronger security practices, including safer remote-access patterns, proper trusted-proxy configuration, and enabling authentication for exposed gateways.
Following the exposure findings, the security community submitted pull requests to harden Clawdbot’s default behavior and make authentication handling more proxy-aware to reduce unauthenticated internet exposure.
Analysis of exposed deployments showed Clawdbot’s localhost-oriented authentication behavior could be bypassed when reverse proxies made external traffic appear to originate from 127.0.0.1. This exposed control interfaces, chat history, API keys, bot tokens, and in some cases command-execution capability.
On 2026-01-23, security researcher Jamieson O’Reilly reported that Shodan-based discovery and follow-on scanning had identified hundreds of publicly reachable Clawdbot instances, with 900+ gateways exposed on port 18789 and many lacking authentication.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
5 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcesecurityonline.info
Open sourcethecyberedition.com
Open sourcecybersecuritynews.com
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.