Description
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may be used for attacks.
Published: 2026-07-18
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The weakness in GoClaw’s matchesAllowlist function allows a client to request approval for actions that should not be authorized, effectively bypassing the intended access control. This leads to a privilege escalation scenario where unauthorized operations can be performed, potentially compromising confidentiality, integrity, or availability of protected resources. The flaw is identified as a failure in authorization and access control, linked to the CWE-285 and CWE-863 categories.

Affected Systems

Vendors affected: nextlevelbuilder:GoClaw, with all releases up to and including version 3.13.2. The vulnerability originates in internal/tools/exec_approval.go and impacts the RequestApproval/matchesAllowlist functionality within the GoClaw codebase.

Risk and Exploitability

The CVSS score of 4.8 places this flaw in a low‑to‑medium severity range, while the EPSS score of <1% indicates a low likelihood of real‑world exploitation currently. Based on the description, it is inferred that the likely attack vector is remote network interaction with the approval workflow. Because the flaw allows remote authorization bypass without requiring elevated local privileges, an attacker with network access could potentially trigger unauthorized approvals if the affected functionality is exposed to untrusted users. This vulnerability is not listed in the CISA KEV catalog, but the public release of an exploit raises the potential for future attacks, especially if the approval workflow is accessible over the network or through APIs.

Generated by OpenCVE AI on July 30, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GoClaw to any version newer than 3.13.2 to eliminate the matchesAllowlist flaw.
  • Restrict network and user access to the approval workflow by implementing role‑based access controls, network segmentation, or firewall rules to limit exposure to trusted administrators.
  • Enable comprehensive audit logging of approval requests and monitor logs for anomalous or unauthorized approvals to detect potential misuse early.

Generated by OpenCVE AI on July 30, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may be used for attacks.
Title nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization
First Time appeared Nextlevelbuilder
Nextlevelbuilder goclaw
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:nextlevelbuilder:goclaw:*:*:*:*:*:*:*:*
Vendors & Products Nextlevelbuilder
Nextlevelbuilder goclaw
References
Metrics cvssV2_0

{'score': 4.7, 'vector': 'AV:A/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Nextlevelbuilder Goclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-20T13:37:14.400Z

Reserved: 2026-07-17T15:56:57.968Z

Link: CVE-2026-16122

cve-icon Vulnrichment

Updated: 2026-07-20T13:37:10.324Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:00:22Z

Weaknesses