Impact
The flaw resides in the isSafeBin function of internal/tools/exec_approval.go, where the code fails to enforce proper authorization checks before allowing binary execution. This improper authorization can be triggered remotely, permitting an attacker to execute arbitrary binaries on the host and thereby compromise confidentiality, integrity, and potentially availability of the affected system. The weakness is rooted in the principles covered by CWE‑266 and CWE‑285, which describe compromised access control mechanisms.
Affected Systems
Nextlevelbuilder’s GoClaw application, in all releases up to and including version 3.13.2, is impacted. Users running any legacy instance of this tool are susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the EPSS score of less than 1% shows only a low probability of widespread exploitation. Nevertheless, a publicly documented exploit exists, and the vulnerability can be leveraged from a remote context, making it a valid security concern. The issue is not listed in the CISA KEV catalog, yet its remote nature and available exploit code suggest that administrators should treat it with priority proportional to their exposure risk.
OpenCVE Enrichment