Impact
A flaw in the receiver_thread function of the http_request module in zevorn rt‑claw allows an attacker to supply crafted data that causes the server to send HTTP requests on the attacker’s behalf. This server‑side request forgery (CWE‑918) can be used to reach internal resources, exfiltrate information, or launch further attacks from the compromised server.
Affected Systems
The vulnerability affects zevorn rt‑claw releases up to and including version 0.2.0. Any deployment running these releases of the swarm component is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as moderate severity. The EPSS score is below 1%, indicating a low current probability of exploitation, yet a public exploit is available, meaning attackers could target vulnerable systems when discovered. The CVE is not listed in the CISA KEV catalog, so widespread weaponized use has not been documented, but the remote attack surface and potential for internal compromise remain significant.
OpenCVE Enrichment