Impact
The handleNavigate function in nextlevelbuilder GoClaw allows an attacker to supply a crafted targetUrl argument that results in the disclosure of sensitive data processed by the tool. The flaw does not permit code execution or denial of service; it solely exposes information, satisfying CWE-200 and CWE-284 characteristics of information disclosure and insufficient access control.
Affected Systems
Versions of GoClaw up to 3.13.3‑beta.3 are affected. The vulnerability resides in pkg/browser/tool.go and affects all deployments of the nextlevelbuilder GoClaw repository that use these releases.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate range, while an EPSS of <1% suggests a low likelihood of exploitation in the wild. The flaw can be exploited remotely by sending a crafted request that manipulates the targetUrl; it is not listed in the CISA KEV catalog.
OpenCVE Enrichment