PT-2026-57931 · Git+1 · Clawlet

·

CVE-2026-15619

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mosaxiv clawlet versions prior to 0.2.11
Description A server-side request forgery (SSRF) exists in the IPv4 Handler component. This occurs when the url argument is manipulated within the web fetch() function located in the tools/tool web fetch.go file, allowing a remote attacker to initiate unauthorized requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the use of the web fetch() function to minimize the risk of exploitation.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15619

Affected Products

Clawlet