Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery
CVE-2026-15624
Description
A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected products
1- Range: 3.13.3-beta.3
Patches
Vulnerability mechanics
References
5- github.com/nextlevelbuilder/goclaw/issues/1199mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-15624mitrethird-party-advisory
- vuldb.com/submit/855798mitrethird-party-advisory
- vuldb.com/vuln/378126mitrevdb-entrytechnical-description
- vuldb.com/vuln/378126/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.