Junglewise Threat Intelligence

CVE-2026-10583: nextlevelbuilder GoClaw SSRF in TTS Configuration Endpoint

CVE-2026-10583 · Severity: medium · CVSS 4.7 · Published 2026-06-02

Technologies: Nextlevelbuilder GoClaw. Vendors: Nextlevelbuilder.

Executive brief

GoClaw, an AI agent platform, contains a security vulnerability in its text-to-speech (TTS) configuration component. An attacker with administrative privileges can force the server to make unauthorized requests to internal or external network resources. This could lead to the exposure of sensitive internal data or be used to pivot into private network segments.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in nextlevelbuilder GoClaw versions up to 3.11.3. The flaw is located in the 'Import' function within 'internal/http/tts_config.go' due to unvalidated TTS provider API base configurations. A remote attacker with high privileges (PR:H) can manipulate the TTS configuration endpoint to initiate requests from the server to arbitrary destinations. This can be used to scan internal networks, access local services, or exfiltrate data from the server's environment. The exploit has been disclosed publicly.

Affected products

  • nextlevelbuilder GoClaw up to 3.11.3

Timeline

  • 2026-06-02: advisory: NVD publication date
  • 2026-06-02: disclosed: Public disclosure of the vulnerability and exploit

References

Related threats