Junglewise Threat Intelligence

CVE-2026-16127: zevorn rt-claw SSRF in http_request tool

CVE-2026-16127 · Severity: high · CVSS 7.3 · Published 2026-07-18

Technologies: Zevorn Rt-Claw. Vendors: Zevorn.

Executive brief

zevorn rt-claw is an AI assistant framework. A vulnerability in its network tool allows remote users to force the assistant to make unauthorized web requests to internal systems or local services. This could allow an attacker to bypass firewalls and read sensitive data from private internal servers that are otherwise not accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `http_request` tool of zevorn rt-claw through version 0.2.0. The functions `claw_net_get` and `claw_net_post` in `claw/tools/tool_net.c` accept user-supplied URLs and pass them to the underlying HTTP client (libcurl on Linux) without validation. Because the AI assistant processes tool calls automatically from untrusted input channels (like Telegram or Feishu), a remote attacker can provide a URL pointing to loopback (127.0.0.1) or private RFC1918 network ranges. The application then fetches the internal resource and returns the response body to the attacker. As of the advisory date, no patch is available.

Affected products

  • zevorn rt-claw <= 0.2.0

Timeline

  • 2026-07-18: advisory: Vulnerability published by VulDB/NVD
  • 2026-06-12: other: Vulnerability details and PoC shared in GitHub issue report

References

Related threats