CVE-2026-10583

Source
https://cve.org/CVERecord?id=CVE-2026-10583
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10583.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10583
Published
2026-06-02T02:45:08.811Z
Modified
2026-07-24T03:57:13.939494267Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery
Details

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10583.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/nextlevelbuilder/goclaw

Affected ranges

Type
GIT
Repo
https://github.com/nextlevelbuilder/goclaw
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "3.11.0"
        },
        {
            "last_affected": "3.11.0"
        },
        {
            "introduced": "3.11.1"
        },
        {
            "last_affected": "3.11.1"
        },
        {
            "introduced": "3.11.2"
        },
        {
            "last_affected": "3.11.2"
        },
        {
            "introduced": "3.11.3"
        },
        {
            "last_affected": "3.11.3"
        }
    ]
}

Affected versions

3.*
3.11.0
3.11.1
3.11.2
3.11.3
lite-v3.*
lite-v3.9.1
v3.*
v3.11.0
v3.11.1
v3.11.2
v3.11.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10583.json"