CVE-2026-7505
nextlevelbuilder GoClaw/GoClaw Lite RPC improper authorization
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.4%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
30 Apr 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9.0 mitigates this issue. Patch name: 406022e79f4a18b3070a446712080571eff11e30. You should upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
public PoCs found — 1
cve_referencegithub.com/nextlevelbuilder/goclaw/issues/866unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/nextlevelbuilder/goclaw/https://github.com/nextlevelbuilder/goclaw/commit/406022e79f4a18b3070a446712080571eff11e30https://github.com/nextlevelbuilder/goclaw/issues/866https://github.com/nextlevelbuilder/goclaw/pull/950https://github.com/nextlevelbuilder/goclaw/releases/tag/v3.9.0https://vuldb.com/submit/803458https://vuldb.com/vuln/360314https://vuldb.com/vuln/360314/cti