Junglewise Threat Intelligence

CVE-2026-16124: nextlevelbuilder GoClaw SSRF in web_fetch component

CVE-2026-16124 · Severity: medium · CVSS 6.3 · Published 2026-07-18

Technologies: Nextlevelbuilder GoClaw. Vendors: Nextlevelbuilder.

Executive brief

GoClaw, a Go-based platform for deploying AI agents, contains a security flaw in its web fetching tool. An attacker with basic access can bypass security filters to make the server send requests to internal network addresses that should be restricted. This could allow an unauthorized user to probe internal infrastructure or access sensitive data within the private network where the server is hosted.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `web_fetch` component of GoClaw due to an incomplete IP address blocklist in the `CheckSSRF` and `isPrivateIP` functions within `internal/tools/web_shared.go`. The validator fails to include special-use IPv4 ranges, specifically `198.18.0.0/15` (RFC 2544) and `240.0.0.0/4`. An authenticated attacker with at least `RoleOperator` privileges can exploit this by invoking the `web_fetch` tool via the `POST /v1/tools/invoke` endpoint, directing the server to issue outbound requests to these restricted internal ranges. This bypass allows for internal port scanning or interaction with internal services. The issue is resolved in version 3.15.0-beta.33 by updating the blocklist.

Affected products

  • nextlevelbuilder GoClaw up to 3.15.0-beta.32

Timeline

  • 2026-07-18: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-07-18: advisory
  • 2026-07-18: patched: Fixed in version 3.15.0-beta.33 via commit 12a0168271827650ddb0026d6277fbadf3dcf3ea.

References

Related threats