CVE-2026-16123

Source
https://cve.org/CVERecord?id=CVE-2026-16123
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16123.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16123
Published
2026-07-18T14:45:08.338Z
Modified
2026-07-22T05:29:52.438462786Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
Details

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16123.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-862",
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/nextlevelbuilder/goclaw

Affected ranges

Type
GIT
Repo
https://github.com/nextlevelbuilder/goclaw
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "3.13.0"
        },
        {
            "last_affected": "3.13.0"
        },
        {
            "introduced": "3.13.1"
        },
        {
            "last_affected": "3.13.1"
        },
        {
            "introduced": "3.13.2"
        },
        {
            "last_affected": "3.13.2"
        }
    ]
}

Affected versions

3.*
3.13.0
3.13.1
3.13.2
v3.*
v3.13.0
v3.13.1
v3.13.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16123.json"