Impact
A flaw in the ExecTool.Execute function of GoClaw allows an attacker to manipulate the execution path, resulting in improper authorization that can be triggered through a crafted manipulation; the attack may be launched remotely by sending a crafted request to the ExecTool.Execute endpoint. The vulnerability exists in nextlevelbuilder’s GoClaw product up through version 3.13.3‑beta.3, so all systems running any release at or below that version are potentially vulnerable, and upgrading to a later unqualified release eliminates the flaw.
Affected Systems
The vulnerability impacts the GoClaw tool developed by nextlevelbuilder, specifically all releases up to and including version 3.13.3‑beta.3. Systems running these versions are eligible to be exploited.
Risk and Exploitability
The vulnerability is enabled by a flaw that removes or bypasses authorization checks before executing privileged commands. Attackers can send a crafted request to the ExecTool.Execute interface and execute arbitrary commands in the context of the system’s service account. The CVSS score of 5.3 grades the incident as moderate severity, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at the moment. The vulnerability is not listed in CISA’s KEV catalog, but the published exploit on GitHub suggests a limited but existing risk for administrators who have not applied the latest update.
OpenCVE Enrichment