Description
A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
Problem types
Product status
3.11.1
3.11.2
3.11.3
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
Eric-b (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/367498 (VDB-367498 | nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection)
vuldb.com/vuln/367498/cti (VDB-367498 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10219 (CVE-2026-10219 | CVE Analysis and Report)
vuldb.com/submit/821939 (Submit #821939 | nextlevelbuilder goclaw <= v3.11.3 OS Command Injection (CWE-78))
github.com/nextlevelbuilder/goclaw/issues/1121
github.com/nextlevelbuilder/goclaw/pull/1155
github.com/nextlevelbuilder/goclaw/