Impact
A remote attacker can manipulate the URL argument to the claw_net_get/claw_net_post functions in zevorn RT‑Claw, causing the application to make outbound HTTP requests that the attacker controls. This server‑side request forgery can be used to probe internal network services, access restricted resources, or exfiltrate data. The weakness is the improper validation of user‑supplied URLs and is classified as CWE‑918.
Affected Systems
zevorn RT‑Claw, versions up to and including 0.2.0. No other vendors or product lines are affected.
Risk and Exploitability
The CVSS score of 6.9 places the vulnerability in the medium‑to‑high severity range. The EPSS score is below 1 %, indicating a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is remote and URL, after which the server will attempt the request to the specified target.
OpenCVE Enrichment