Executive brief
GoClaw, a tool used for deploying AI agent teams with multi-tenant isolation, contains a vulnerability that allows for remote command execution. By manipulating file paths, an attacker can bypass security sandboxes to run unauthorized commands on the underlying system. This could lead to a complete compromise of the sandbox environment, potentially exposing customer data or allowing attackers to disrupt operations.
Technical details
An OS command injection vulnerability exists in GoClaw's FsBridge.WriteFile function within `internal/sandbox/fsbridge.go`. The root cause is the insecure construction of a shell command using `fmt.Sprintf` to interpolate filenames into a `sh -c` execution string. While the `%q` verb was used for quoting, it fails to neutralize shell metacharacters like command substitutions `$(...)`. A remote attacker can provide a crafted filename containing these metacharacters to achieve arbitrary command execution as root within the sandbox container. A fix has been proposed in pull request #1155 which replaces the shell-based write path with a direct execution of `tee`, passing the filename as a discrete argument to avoid shell evaluation.
Affected products
- nextlevelbuilder GoClaw <= 3.11.3
Timeline
- 2026-05-19: patched: Pull request #1155 submitted to fix the injection issue.
- 2026-06-01: disclosed: Vulnerability disclosed and CVE-2026-10219 assigned.