Impact
A flaw in the WriteFile operation of nextlevelbuilder's GoClaw component permits attackers to inject arbitrary operating‑system commands. The defect arises when external input is passed unsanitized to the system shell, allowing malicious payloads to be executed with the privileges of the running process. This can lead to full compromise of the host, data theft, and further lateral movement within an environment that consumes this tool.
Affected Systems
The vulnerability affects nextlevelbuilder's GoClaw tool through version 3.11.3, specifically the FsBridge.WriteFile function in internal/sandbox/fsbridge.go. All releases up to and including 3.11.3 are susceptible; newer releases must be evaluated for the pending patch.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, but the attack vector is remote and the exploit has been made public. The lack of an EPSS score does not diminish the risk; the vulnerability is not listed in the CISA KEV catalog. Because the flaw allows arbitrary command execution over a network interface, the likelihood of exploitation is significant for exposed installations, especially if the tool is reachable from untrusted sources.
OpenCVE Enrichment