CVE-2026-15625

MEDIUM

nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist

Title source: cna
STIX 2.1

Description

A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit has been made public and could be used.

References (12)

Core 12
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-378127 | nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist
https://vuldb.com/vuln/378127
Signature, Permissions Required signature permissions-required
VDB-378127 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/378127/cti
Third Party Advisory third-party-advisory
CVE-2026-15625 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15625
Third Party Advisory third-party-advisory
Submit #855804 | nextlevelbuilder GoClaw 3.11.3 Command Execution Policy Bypass (CWE-184)
https://vuldb.com/submit/855804
Third Party Advisory third-party-advisory
Submit #855806 | nextlevelbuilder GoClaw 3.13.2 Command Execution Policy Bypass (CWE-184) (Duplicate)
https://vuldb.com/submit/855806
Third Party Advisory third-party-advisory
Submit #855807 | nextlevelbuilder GoClaw 3.13.3-beta.3 Authorization Bypass (CWE-863) (Duplicate)
https://vuldb.com/submit/855807
Third Party Advisory third-party-advisory
Submit #855845 | nextlevelbuilder GoClaw 3.13.3-beta.3 Command Execution Policy Bypass (CWE-184) (Duplicate)
https://vuldb.com/submit/855845
Third Party Advisory third-party-advisory
Submit #855846 | nextlevelbuilder GoClaw 3.13.2 Improper Authorization (CWE-285) (Duplicate)
https://vuldb.com/submit/855846
Third Party Advisory third-party-advisory
Submit #855848 | nextlevelbuilder GoClaw 3.13.2 OS Command Injection (CWE-78) (Duplicate)
https://vuldb.com/submit/855848

Scores

CVSS v3 6.3
EPSS 0.0028
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-183 CWE-184
Status published
Products (1)
nextlevelbuilder/GoClaw 3.11.3
Published Jul 14, 2026
Tracked Since Jul 14, 2026