Impact
A weakness in the web_fetch function of tools/tool_web_fetch.go in the IPv4 Handler component allows an attacker to manipulate the URL argument and force the Clawlet server to perform arbitrary HTTP requests. This vulnerability is a classic server‑side request forgery that can be triggered remotely. The flaw is identified as CWE‑918 and an exploit has been made available publicly.
Affected Systems
The vulnerable product is mosaxiv Clawlet, all releases up to and including version 0.2.10. Earlier versions lack the fix and are therefore affected.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can send crafted requests that cause the Clawlet server to contact arbitrary URLs, potentially exposing the server to unintended resources, but the description does not confirm successful exploitation beyond that capability.
OpenCVE Enrichment