Description
A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Published: 2026-07-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication flaw exists in the RequestApproval function of GoClaw’s WebSocket Approval Endpoint, caused by improper handling of authorization data. By manipulating the request, an attacker can gain unauthorized approval privileges. The flaw is identified as CWE‑285 (Improper Authorization) and CWE‑863 (Missing Authorization). This flaw can enable remote actors to approve or execute actions that should be restricted, potentially compromising the integrity and confidentiality of the system that relies on these approvals.

Affected Systems

The vulnerability affects GoClaw produced by NextLevelBuilder, in all releases up to and including version 3.13.2. The flaw is located in the internal/tools/exec_approval.go component of the WebSocket Approval Endpoint. Systems using any of these vulnerable versions are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at any given time. The vulnerability is not listed in CISA’s KEV catalog. The attack is possible to be carried out remotely and the exploit code has been publicly released, meaning a determined adversary could potentially use the flaw to acquire unauthorized approvals.

Generated by OpenCVE AI on July 30, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GoClaw to a version later than 3.13.2 when it becomes available, or apply any vendor‑supplied patch that addresses the RequestApproval authorization issue.
  • If upgrading is not immediately feasible, disable or restrict access to the WebSocket Approval Endpoint, ensuring only trusted users or systems can reach it.
  • Implement additional authorization checks on the server side for all approval requests, ensuring that the requester’s permissions are validated before any approval action is performed.

Generated by OpenCVE AI on July 30, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Title nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
First Time appeared Nextlevelbuilder
Nextlevelbuilder goclaw
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:nextlevelbuilder:goclaw:*:*:*:*:*:*:*:*
Vendors & Products Nextlevelbuilder
Nextlevelbuilder goclaw
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Nextlevelbuilder Goclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-21T02:35:00.721Z

Reserved: 2026-07-17T15:56:44.538Z

Link: CVE-2026-16119

cve-icon Vulnrichment

Updated: 2026-07-21T02:34:46.805Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses