Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cua (YC X25)

Cua (YC X25) Vendor Cyber Rating & Cyber Score

github.com

Cua is an open-source framework that enables AI agents to control full operating systems within high-performance, lightweight virtual containers. It delivers up to 90% native speed on Apple Silicon and works with any language models. Cua is backed by Y Combinator, and part of the X25 batch.


C A.I CyberSecurity Scoring

C
Company Information
Website:https://github.com/trycua/cua
Employees number:6
Number of followers:2,063
NAICS:5112
Industry Type:Software Development
Homepage:github.com
C Risk Score (AI oriented)
Between 700 and 749
logo
CSoftware Development
Updated:
10/03/2026
747/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
C Global Score (TPRM)
xxxx
logo
CSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

C
CModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
748Before Incident
MAY 2026
747Before Incident
APRIL 2026
747Before Incident
MARCH 2026
747Before Incident
FEBRUARY 2026
747Before Incident
JANUARY 2026
749Before Incident
Vulnerability
28 Jan 2026C
ClawDBot: Critical 1-Click Clawdbot Vulnerability Allows Malicious RCE Exploitation

Critical Authentication Bypass Flaw in ClawDBot Enables Remote Code Execution

747After Incident
CRITICAL-2
CUA1770021700
Critical Authentication Bypass Flaw in ClawDBot Enables Remote Code Execution A high-severity vulnerability (GHSA-g8p2-7wf7-98mq) in ClawDBot, a widely used npm package, allows attackers to bypass authentication and achieve remote code execution (RCE) via a single malicious link. The flaw affects versions up to v2026.1.28 and stems from inadequate validation of the `gatewayUrl` parameter in the Control UI. ### Exploitation Mechanism The vulnerability exploits automatic WebSocket connections initiated on page load, which transmit stored gateway authentication tokens to the specified endpoint without validation. Attackers can craft a malicious URL or phishing site containing a controlled `gatewayUrl`, tricking users into clicking it. When accessed by an authenticated victim, the token is automatically exfiltrated to the attacker’s server no further interaction is required. Once compromised, the token grants operator-level access to the victim’s gateway API, enabling arbitrary configuration changes, sandbox modifications, and ultimately RCE on the host system. The attack is particularly dangerous because it bypasses network isolation even localhost-only or air-gapped instances remain vulnerable if users interact with external links. ### Impact & Mitigation The vendor has patched the issue in ClawDBot v2026.1.29, introducing mandatory user confirmation for new gateway URLs to prevent automatic token transmission. Organizations are urged to upgrade immediately and audit logs for suspicious activity, including: - Unauthorized WebSocket connections to external infrastructure. - Unexpected gateway configuration changes. Additional defenses include egress filtering and deploying ClawDBot behind proxy servers with URL validation. The flaw highlights the risks of automatic token transmission and insufficient parameter validation in authentication workflows.
INCIDENT DETAILS -
TYPE
Authentication Bypass, Remote Code Execution (RCE)
IMPACT
Data Compromised: Gateway authentication tokensSystems Affected: ClawDBot (versions up to v2026.1.28)Operational Impact: Arbitrary configuration changes, sandbox modifications, RCE on host system
DATA BREACH
Type Of Data Compromised: Authentication tokensSensitivity Of Data: High (operator-level access)Data Exfiltration: Yes (tokens transmitted to attacker-controlled server)
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
749Before Incident
SEPTEMBER 2025
749Before Incident
AUGUST 2025
749Before Incident
JULY 2025
749Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for C ?
?
What was C's A.I Rankiteo Cyber Score in May 2026 ?
?
What was C's A.I Rankiteo Cyber Score in April 2026 ?
?
What was C's A.I Rankiteo Cyber Score in March 2026 ?
?
What was C's A.I Rankiteo Cyber Score in February 2026 ?
?
What was C's A.I Rankiteo Cyber Score in January 2026 ?
?
What was C's A.I Rankiteo Cyber Score in December 2025 ?
?
What was C's A.I Rankiteo Cyber Score in November 2025 ?
?
What was C's A.I Rankiteo Cyber Score in October 2025 ?
?
What was C's A.I Rankiteo Cyber Score in September 2025 ?
?
What was C's A.I Rankiteo Cyber Score in August 2025 ?
?
What was C's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on C's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with C ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view C's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?