CVE-2026-16120

Summary

A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

Affected Software

VendorProductVersion RangeStatus
nextlevelbuilderGoClaw3.13.3-beta.0affected
nextlevelbuilderGoClaw3.13.3-beta.1affected
nextlevelbuilderGoClaw3.13.3-beta.2affected
nextlevelbuilderGoClaw3.13.3-beta.3affected

Weaknesses

  • CWE-706: Incorrectly-Resolved Name

References