CVE-2026-16121

Summary

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Affected Software

VendorProductVersion RangeStatus
nextlevelbuilderGoClaw3.13.0affected
nextlevelbuilderGoClaw3.13.1affected
nextlevelbuilderGoClaw3.13.2affected

Weaknesses

  • CWE-285: Improper Authorization
  • CWE-266: Incorrect Privilege Assignment

References