OS Command Injection Vulnerability in Nextlevelbuilder GoClaw Tool
CVE-2026-10219
Key Information:
- Vendor
Nextlevelbuilder
- Status
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-10219?
A vulnerability has been identified in Nextlevelbuilder's GoClaw tool, specifically in the FsBridge.WriteFile function located in internal/sandbox/fsbridge.go. This issue enables os command injection, potentially allowing attackers to execute arbitrary commands on the server remotely. The threat has been made public, heightening the risk for affected systems. A fix for this vulnerability is pending approval in an associated pull request.
Affected Version(s)
GoClaw 3.11.0
GoClaw 3.11.1
GoClaw 3.11.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
