Impact
This issue stems from an error in the matchesAllowlist/extractBin routine in GoClaw, which can be exploited to manipulate name resolution and cause the tool to pick an incorrect binary name. If the tool resolves to a different file than intended, an attacker could gain unauthorized access to or execution of files that are not meant to be selectable, effectively bypassing intended access restrictions. The flaw is identified as CWE‑706, reflective of a privilege or access‑control error.
Affected Systems
Nextlevelbuilder GoClaw versions up to and including 3.13.3‑beta.3 are affected. These versions are used in environments where GoClaw executes approved binaries, and the vulnerability resides in the matchesAllowlist/extractBin function in internal/tools/exec_approval.go. No further specific version details are listed by the CNA.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1 percent suggests that exploitation is not expected to be widespread. The vulnerability is not listed in the CISA KEV catalog. The vulnerability can be exploited remotely, as indicated by the CNA, but the description does not specify whether authentication is required. Given the EPSS figure, widespread exploitation is considered unlikely.
OpenCVE Enrichment