CVE-2026-10218

medium

Description

A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project tagged the reported issue as bug.

References

https://vuldb.com/vuln/367497/cti

https://vuldb.com/vuln/367497

https://vuldb.com/submit/821938

https://vuldb.com/cve/CVE-2026-10218

https://github.com/nextlevelbuilder/goclaw/issues/1120

https://github.com/nextlevelbuilder/goclaw/

Details

Source: Mitre, NVD

Published: 2026-06-01

Updated: 2026-06-01

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00043