Junglewise Threat Intelligence

CVE-2026-16123: nextlevelbuilder GoClaw authorization bypass in ToolsInvokeHandler

CVE-2026-16123 · Severity: medium · CVSS 6.3 · Published 2026-07-18

Technologies: Nextlevelbuilder GoClaw. Vendors: Nextlevelbuilder.

Executive brief

GoClaw is a platform used to deploy and manage AI agent teams. A security flaw in the tool invocation endpoint allows an authenticated user to bypass access controls and schedule tasks (cron jobs) on AI agents belonging to other users. This could lead to unauthorized operations or data access by tricking the system into executing tasks on private agents that the user should not be able to reach.

Technical details

A missing authorization vulnerability exists in GoClaw up to version 3.13.2 within the ToolsInvokeHandler.ServeHTTP function located in internal/http/tools_invoke.go. The handler accepts an attacker-controlled agentId and injects it into the request context without performing a CanAccess check, unlike other agent-related endpoints. When the 'cron' tool is invoked via POST /v1/tools/invoke, this unauthorized agent ID is persisted in the database. The scheduler subsequently trusts this stored binding, allowing a user with operator.write privileges to execute tasks against foreign agents. A public exploit demonstrating this stored authorization bypass has been disclosed.

Affected products

  • nextlevelbuilder GoClaw up to 3.13.2

Timeline

  • 2026-07-18: disclosed: Vulnerability details and PoC made public via GitHub and VulDB
  • 2026-07-18: advisory: CVE-2026-16123 published

References

Related threats