Executive brief
GoClaw, a tool for deploying AI agent teams, contains a security flaw in its browser automation component. An authorized user could trick the system into opening local files on the server instead of web pages. This allows the user to read sensitive information from the server's hard drive, such as configuration files, logs, or security tokens, which they should not be able to access.
Technical details
An information disclosure vulnerability exists in GoClaw up to version 3.13.3-beta.3 within the `handleNavigate` function of `pkg/browser/tool.go`. The application fails to validate the URI scheme of the `args.targetUrl` parameter before passing it to the underlying browser automation library (Rod). A remote authenticated attacker with 'operator' privileges can provide a `file://` URL to force the browser to load local system files. By subsequently using the `snapshot` or `act.evaluate` actions, the attacker can retrieve the contents of any file readable by the OS user running the GoClaw process. As of the advisory date, no patch is available.
Affected products
- nextlevelbuilder GoClaw up to 3.13.3-beta.3
Timeline
- 2026-07-14: advisory: NVD publication date