CVE-2026-10218 Details
Description
A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project tagged the reported issue as bug.
A vulnerability exists in GoClaw versions up to 3.11.3, specifically within the evolution suggestion management feature. The issue arises in the 'auth' function of 'internal/http/evolution_handlers.go', where the authorization middleware is improperly configured. This flaw allows unauthorized or low-privilege users to manipulate system-generated evolution suggestions, such as approving or rejecting them. Such actions can disrupt tenant configurations and agent behaviors, leading to significant functional degradations across the platform.
Users can update to GoClaw version 3.11.4 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextlevelbuilder/goclaw/ | [email protected] | Source CodeVendor |
| https://github.com/nextlevelbuilder/goclaw/issues/1120 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-10218 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/821938 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/367497 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/367497/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextlevelbuilder GoClaw | <= 3.11.3 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion