GHSA-6jm8-4fhr-5w64

Suggest an improvement
Source
https://github.com/advisories/GHSA-6jm8-4fhr-5w64
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6jm8-4fhr-5w64/GHSA-6jm8-4fhr-5w64.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6jm8-4fhr-5w64
Aliases
Published
2026-06-01T06:30:25Z
Modified
2026-07-21T19:18:59Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
GoClaw has a Command Injection issue
Details

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cwe_ids":  [
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-09T20:49:44Z",
    "nvd_published_at":  "2026-06-01T04:16:21Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/nextlevelbuilder/goclaw

Package

Name
github.com/nextlevelbuilder/goclaw
View open source insights on deps.dev
Purl
pkg:golang/github.com/nextlevelbuilder/goclaw

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.11.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6jm8-4fhr-5w64/GHSA-6jm8-4fhr-5w64.json"