Impact
The bytePlusDownloadVideo function in nextlevelbuilder GoClaw version 3.13.3‑beta.3 allows an attacker to supply a crafted output.video_url that forces the server to fetch arbitrary URLs, enabling SSRF. The flaw is in the invoke Endpoint within internal/tools/create_video_byteplus.go and remote exploitation is possible without validating the target address.
Affected Systems
Affected product is nextlevelbuilder GoClaw version 3.13.3‑beta.3. No other versions were listed as vulnerable in the CNA data, and the issue is confined to the bytePlusDownloadVideo function used by the invoke Endpoint.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability presents a moderate risk, and the EPSS score of less than 1% indicates a very low probability of exploitation at this time. It is not listed in the CISA KEV catalog. The flaw is a server‑side request forgery that allows arbitrary URLs. Based on the description, it is inferred that this could potentially expose internal resources or lead to abuse of outbound bandwidth, depending on the GoClaw deployment’s network environment, and might enable attackers to reach internal services or exhaust network resources.
OpenCVE Enrichment