PT-2026-57953 · Nextlevelbuilder+1 · Goclaw
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
nextlevelbuilder GoClaw version 3.11.3
Description
A remote attack is possible due to an issue in the
ExecApprovalManager.CheckCommand() function within the internal/tools/exec approval.go file. This flaw allows for the manipulation of the blacklist, resulting in an incomplete blacklist that can be bypassed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
ExecApprovalManager.CheckCommand() function to minimize the risk of exploitation.Exploit
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goclaw