PT-2026-57953 · Nextlevelbuilder+1 · Goclaw

·

CVE-2026-15625

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nextlevelbuilder GoClaw version 3.11.3
Description A remote attack is possible due to an issue in the ExecApprovalManager.CheckCommand() function within the internal/tools/exec approval.go file. This flaw allows for the manipulation of the blacklist, resulting in an incomplete blacklist that can be bypassed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the ExecApprovalManager.CheckCommand() function to minimize the risk of exploitation.

Exploit

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15625

Affected Products

Goclaw