Impact
The flaw resides in the claw_tool_invoke routine of the RPC handler in rt‑claw. The code fails to validate authorization properly, enabling an attacker to manipulate the RPC request and gain unauthorized access to privileged functionality. Remote exploitation is possible, allowing the attacker to execute arbitrary RPC commands that should be restricted, potentially leading to data leakage, tampering or further compromise of the host.
Affected Systems
Vendors affected: zevorn. Product: rt‑claw. Versions impacted include all releases up to and including 0.2.0. No later versions are known to contain a fix.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS is below 1 %, suggesting a low likelihood of exploitation in the wild, and it is not currently listed in CISA’s KEV catalog. Attackers would need to reach the RPC endpoint, likely via the network, and craft a malicious request that bypasses the missing authorization checks. Once successful, they could run any command or operation exposed by the RPC interface.
OpenCVE Enrichment