PT-2026-33757 · Rowboat · Rowboat
Davidgilmore
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6635
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rowboat versions prior to 0.1.68
Description
Improper authentication occurs in the tools webhook component within the
tool call() function of the 'apps/experimental/tools webhook/app.py' file. A remote attacker can manipulate the X-Tools-JWE argument to bypass authentication mechanisms.Recommendations
Update to a version newer than 0.1.67.
As a temporary workaround, restrict access to the
tool call() function or the 'apps/experimental/tools webhook/app.py' file to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rowboat