Impact
The vulnerability resides in the ToolsInvokeHandler.ServeHTTP handler of the GoClaw Invoke Endpoint. By manipulating the request framework’s authorization checks, remote users can invoke privileged tools without authentication. This missing authorization exposes sensitive operations and data and could enable further exploitation.
Affected Systems
nextlevelbuilder GoClaw, versions up to and including 3.13.2, are affected. The issue is confined to the internal/http/tools_invoke.go component and any deployment that exposes the invoke endpoint is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while an EPSS score under 1% shows a low probability of widespread exploitation. The vulnerability can be triggered remotely; exploit code has been publicly released. The attack is likely feasible on servers with an exposed invoke endpoint, though the attacker must identify a valid target. Since it is not currently listed in the CISA KEV catalog, no coordinated response has been issued yet.
OpenCVE Enrichment