Impact
The flaw occurs in the functions that process HTTP GET and POST requests in the net.c file of the rt‑claw component. A remote attacker can manipulate input parameters to these functions, causing the application to unintentionally expose data that should remain confidential. This is a case of Information Exposure (CWE‑200) combined with Improper Authorization (CWE‑284), allowing unauthenticated data leakage.
Affected Systems
Affected systems are installations of zevorn rt‑claw up to and including version 0.2.0. The vulnerability is present in the http_request service module across all builds before this release. A fix is not yet available and the vendor has not responded to the issue report.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1 % shows a low probability of widespread exploitation at present. The exploit is publicly available and can be triggered remotely, and the vulnerability is not listed in CISA’s KEV catalog. The risk is heightened where untrusted traffic is allowed to reach the vulnerable component, enabling an attacker to obtain confidential data without authentication.
OpenCVE Enrichment