Feed/CVE-2026-10219
CVE-2026-10219HIGHCVSS 7.3

GoClaw has a Command Injection issue

Published Jun 1, 2026·Updated Jul 22, 2026

NVD Description

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

Affected Packages (1)

github.com/nextlevelbuilder/goclawGO
Fixed in = 3.11.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free