Impact
The vulnerability occurs in the http_request component of zevorn rt‑claw prior to version 0.2.0. Manipulating the URL argument passed to the claw_net_get or claw_net_post functions allows an attacker to force the server to issue arbitrary HTTP requests, which is a server‑side request forgery. Based on the description, it is inferred that an attacker could probe internal resources, exfiltrate data, or bypass network boundaries. The exploitation is remote and publicly available exploit code suggests an attacker could automate the attack.
Affected Systems
All installations of zevorn rt‑claw up to and including 0.2.0 are affected. The vulnerable code resides in claw/tools/tool_net.c and specifically in the claw_net_get/claw_net_post functions.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as medium severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, further indicating limited known exploitation. Nevertheless, because the attack vector is remote and the public exploit code is available, system owners should assess whether the rt‑claw instance is exposed to untrusted input or network traffic before deciding on remediation measures.
OpenCVE Enrichment