Executive brief
mosaxiv clawlet is a lightweight AI assistant tool. A security flaw in its web fetching component allows an attacker to force the application to make unauthorized requests to internal systems or local services. This could result in the exposure of sensitive internal data, access to private administrative panels, or the ability to probe the internal network from the server's perspective.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `tools.webFetch` function within `tools/tool_web_fetch.go` of mosaxiv clawlet. The issue stems from a default configuration in `config.go` that uses a wildcard allowlist (`*`) for domains and a lack of runtime validation to block loopback (127.0.0.1/localhost) or private RFC1918 IP addresses. A remote attacker with the ability to trigger the `web_fetch` tool can coerce the host into requesting internal HTTP targets and retrieve the response body. As of the advisory date, the GitHub issue was closed as 'not planned,' indicating no official patch is available.
Affected products
- mosaxiv clawlet <= 0.2.10
Timeline
- 2026-07-14: advisory: NVD publication date
- 2026-07-14: disclosed: Public disclosure of the exploit and GitHub issue