Description
A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-07-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the claw_tool_invoke routine of the RPC handler in rt‑claw. The code fails to validate authorization properly, enabling an attacker to manipulate the RPC request and gain unauthorized access to privileged functionality. Remote exploitation is possible, allowing the attacker to execute arbitrary RPC commands that should be restricted, potentially leading to data leakage, tampering or further compromise of the host.

Affected Systems

Vendors affected: zevorn. Product: rt‑claw. Versions impacted include all releases up to and including 0.2.0. No later versions are known to contain a fix.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS is below 1 %, suggesting a low likelihood of exploitation in the wild, and it is not currently listed in CISA’s KEV catalog. Attackers would need to reach the RPC endpoint, likely via the network, and craft a malicious request that bypasses the missing authorization checks. Once successful, they could run any command or operation exposed by the RPC interface.

Generated by OpenCVE AI on July 30, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the running rt‑claw version and update to the latest release if it addresses the issue; if no patch is available, consider moving to a newer version that resolves the bug.
  • If upgrading is not an option, restrict network access to the RPC service by placing it behind a firewall or VPN and allow only trusted hosts to communicate with it.
  • Audit and monitor RPC logs for anomalous activity, and apply additional authentication or rate‑limiting controls at the network or application level to reduce the risk of abuse.

Generated by OpenCVE AI on July 30, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 19 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title zevorn rt-claw RPC swarm.c claw_tool_invoke authorization
First Time appeared Zevorn
Zevorn rt-claw
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:zevorn:rt-claw:*:*:*:*:*:*:*:*
Vendors & Products Zevorn
Zevorn rt-claw
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-20T13:55:35.771Z

Reserved: 2026-07-18T07:29:32.332Z

Link: CVE-2026-16200

cve-icon Vulnrichment

Updated: 2026-07-20T13:55:32.101Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:00:22Z

Weaknesses