CVE-2026-16199

Summary

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used.

Affected Software

VendorProductVersion RangeStatus
nextlevelbuilderGoClaw3.13.3-beta.0affected
nextlevelbuilderGoClaw3.13.3-beta.1affected
nextlevelbuilderGoClaw3.13.3-beta.2affected
nextlevelbuilderGoClaw3.13.3-beta.3affected

Weaknesses

  • CWE-285: Improper Authorization
  • CWE-266: Incorrect Privilege Assignment

References