← Volver al buscador de CVEs

CVE-2026-10219

nextlevelbuilder GoClaw

Descripción

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

CVSS 7.3EPSS 1.336%Riesgo 0.82
Ver fuente
Publicación
2026-06-01 04:16:21
Versiones afectadas
<=3.11.3
Tipo
Core software
Última modificación
2026-07-22 07:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L