nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_bridge.go of the component ACP ToolBridge Workspace Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
nextlevelbuilder · GoClawpublic PoCs found — 1
cve_referencegithub.com/nextlevelbuilder/goclaw/issues/1201unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/nextlevelbuilder/goclaw/https://github.com/nextlevelbuilder/goclaw/issues/1201https://github.com/nextlevelbuilder/goclaw/issues/1201#issuecomment-4760748680https://vuldb.com/cve/CVE-2026-15626https://vuldb.com/submit/855805https://vuldb.com/vuln/378128https://vuldb.com/vuln/378128/cti