Impact
An authentication flaw exists in the RequestApproval function of GoClaw’s WebSocket Approval Endpoint, caused by improper handling of authorization data. By manipulating the request, an attacker can gain unauthorized approval privileges. The flaw is identified as CWE‑285 (Improper Authorization) and CWE‑863 (Missing Authorization). This flaw can enable remote actors to approve or execute actions that should be restricted, potentially compromising the integrity and confidentiality of the system that relies on these approvals.
Affected Systems
The vulnerability affects GoClaw produced by NextLevelBuilder, in all releases up to and including version 3.13.2. The flaw is located in the internal/tools/exec_approval.go component of the WebSocket Approval Endpoint. Systems using any of these vulnerable versions are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at any given time. The vulnerability is not listed in CISA’s KEV catalog. The attack is possible to be carried out remotely and the exploit code has been publicly released, meaning a determined adversary could potentially use the flaw to acquire unauthorized approvals.
OpenCVE Enrichment