CVE-2026-10219: GoClaw has a Command Injection issue
(updated )
A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
References
- github.com/advisories/GHSA-6jm8-4fhr-5w64
- github.com/nextlevelbuilder/goclaw
- github.com/nextlevelbuilder/goclaw/issues/1121
- github.com/nextlevelbuilder/goclaw/pull/1155
- nvd.nist.gov/vuln/detail/CVE-2026-10219
- vuldb.com/cve/CVE-2026-10219
- vuldb.com/submit/821939
- vuldb.com/vuln/367498
- vuldb.com/vuln/367498/cti
Code Behaviors & Features
Detect and mitigate CVE-2026-10219 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →