High severity7.3NVD Advisory· Published Jun 1, 2026· Updated Jul 22, 2026
CVE-2026-10219
CVE-2026-10219
Description
A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/nextlevelbuilder/goclawGo | <= 3.11.3 | — |
Affected products
2- Range: <=3.11.3
- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-6jm8-4fhr-5w64ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-10219ghsaADVISORY
- github.com/nextlevelbuilder/goclaw/issues/1121nvdWEB
- github.com/nextlevelbuilder/goclaw/pull/1155nvdWEB
- vuldb.com/cve/CVE-2026-10219nvdWEB
- vuldb.com/submit/821939nvdWEB
- vuldb.com/vuln/367498nvdWEB
- vuldb.com/vuln/367498/ctinvdWEB
News mentions
0No linked articles in our index yet.