Junglewise Threat Intelligence

CVE-2026-15624: nextlevelbuilder GoClaw SSRF in bytePlusDownloadVideo

CVE-2026-15624 · Severity: medium · CVSS 6.3 · Published 2026-07-14

Technologies: Nextlevelbuilder GoClaw. Vendors: Nextlevelbuilder.

Executive brief

nextlevelbuilder GoClaw is an AI agent deployment platform. A security flaw in its video generation component allows the system to be tricked into making unauthorized network requests to internal servers. An attacker with basic access could use this to scan private company networks or access sensitive internal data that is not intended to be public.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `bytePlusDownloadVideo` function within `internal/tools/create_video_byteplus.go` of GoClaw 3.13.3-beta.3. The application trusts provider-returned media download URLs and fetches them using a standard `http.Client` without applying the project's existing SSRF protections or pinned-IP validation. An authenticated operator can invoke the `create_video` tool; if the upstream provider (or a spoofed provider) returns a malicious `video_url`, the server will execute a GET request to that URL from its own network context. This allows access to loopback interfaces, metadata endpoints, and other internal network resources. Similar unsafe patterns were identified in the Gemini and MiniMax video tool implementations.

Affected products

  • nextlevelbuilder GoClaw 3.13.3-beta.3

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-07-13: disclosed: Public GitHub issue report

References

Related threats