BRIEFING NOTE: CVE-2026-6635 Rowboat Labs' rowboat tool up to version 0.1.67 contains an authentication bypass vulnerability in the tools_webhook component. The flaw exists in the tool_call function of apps/experimental/tools_webhook/app.py, where improper validation of the X-Tools-JWE argument allows attackers to circumvent authentication controls. The vulnerability carries a HIGH severity rating of 7.3 CVSS with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The impact is moderate, affecting confidentiality, integrity, and availability with consequences limited to the vulnerable application scope. This positions it as a significant remote exploitation risk that could lead to unauthorized access and data manipulation. The exploit has been publicly disclosed, and while there is no current evidence of active exploitation in the wild, the vendor has not responded to early disclosure notifications. The FAUCET risk score of 37.0 and presence on the active Hot List suggest ongoing community attention. Organizations running affected versions should prioritize patching beyond version 0.1.67 and implement access controls to restrict unauthenticated tool_webhook requests.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Rowboatlabs | Rowboat | 0.1.0, 0.1.1, 0.1.10, 0.1.11, 0.1.12, 0.1.13, 0.1.14, 0.1.15, 0.1.16, 0.1.17, 0.1.18, 0.1.19, 0.1.2, 0.1.20, 0.1.21, 0.1.22, 0.1.23, 0.1.24, 0.1.25, 0.1.26, 0.1.27, 0.1.28, 0.1.29, 0.1.3, 0.1.30, 0.1.31, 0.1.32, 0.1.33, 0.1.34, 0.1.35, 0.1.36, 0.1.37, 0.1.38, 0.1.39, 0.1.4, 0.1.40, 0.1.41, 0.1.42, 0.1.43, 0.1.44, 0.1.45, 0.1.46, 0.1.47, 0.1.48, 0.1.49, 0.1.5, 0.1.50, 0.1.51, 0.1.52, 0.1.53, 0.1.54, 0.1.55, 0.1.56, 0.1.57, 0.1.58, 0.1.59, 0.1.6, 0.1.60, 0.1.61, 0.1.62, 0.1.63, 0.1.64, 0.1.65, 0.1.66, 0.1.67, 0.1.7, 0.1.8, 0.1.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.