Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GoClaw — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in GoClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product GoClaw. It collects security flaws associated with this specific software component, covering advisories published within the last two years. By reviewing this collection, you can track the vendor's recent security notices, understand the distribution of weakness types affecting the product, and look up its complete vulnerability history. The summary provides a structured overview of known issues without listing individual CVE identifiers, allowing users to assess risk levels and identify recurring patterns in the product's security posture.

Vendor: nextlevelbuilder

CVE ID Title CVSS Severity Published
CVE-2026-18038 nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure CWE-200 4.3 Medium 2026-07-28
CVE-2026-16199 nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization CWE-285 6.3 Medium 2026-07-19
CVE-2026-16124 nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery CWE-918 6.3 Medium 2026-07-18
CVE-2026-16123 nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization CWE-862 6.3 Medium 2026-07-18
CVE-2026-16122 nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization CWE-863 4.3 Medium 2026-07-18
CVE-2026-16121 nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization CWE-285 6.3 Medium 2026-07-18
CVE-2026-16120 nextlevelbuilder GoClaw exec_approval.go extractBin name resolution CWE-706 6.3 Medium 2026-07-18
CVE-2026-16119 nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization CWE-863 6.3 Medium 2026-07-18
CVE-2026-15627 nextlevelbuilder GoClaw tool.go handleNavigate information disclosure CWE-200 4.3 Medium 2026-07-14
CVE-2026-15626 nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal CWE-22 6.3 Medium 2026-07-14
CVE-2026-15625 nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist CWE-184 6.3 Medium 2026-07-14
CVE-2026-15624 nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery CWE-918 6.3 Medium 2026-07-14
CVE-2026-14716 nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authorization CWE-863 6.3 Medium 2026-07-05
CVE-2026-10617 nextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authentication CWE-306 7.3 High 2026-06-02
CVE-2026-10616 nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization CWE-862 4.3 Medium 2026-06-02
CVE-2026-10583 nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery CWE-918 4.7 Medium 2026-06-02
CVE-2026-10219 nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection CWE-78 7.3 High 2026-06-01
CVE-2026-10218 nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization CWE-285 5.4 Medium 2026-06-01
CVE-2026-10217 nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management CWE-269 6.3 Medium 2026-06-01
CVE-2026-7505 nextlevelbuilder GoClaw/GoClaw Lite RPC improper authorization CWE-285 7.3 High 2026-04-30

All 20 known CVE vulnerabilities affecting GoClaw with full Chinese analysis, references, and POCs where available.