CVE-2026-10219

HIGH

nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection

Title source: cna
STIX 2.1

Description

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-367498 | nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection
https://vuldb.com/vuln/367498
Signature, Permissions Required signature permissions-required
VDB-367498 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/367498/cti
Third Party Advisory third-party-advisory
CVE-2026-10219 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-10219
Third Party Advisory third-party-advisory
Submit #821939 | nextlevelbuilder goclaw <= v3.11.3 OS Command Injection (CWE-78)
https://vuldb.com/submit/821939

Scores

CVSS v3 7.3
EPSS 0.0134
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (4)
nextlevelbuilder/GoClaw 3.11.0
nextlevelbuilder/GoClaw 3.11.1
nextlevelbuilder/GoClaw 3.11.2
nextlevelbuilder/GoClaw 3.11.3
Published Jun 01, 2026
Tracked Since Jun 01, 2026