Executive brief
A vulnerability exists in rt-claw, a toolset for AI assistants, that allows attackers to read sensitive files from the server. By providing a specially crafted URL to the application's network request tool, an attacker can bypass intended restrictions and access local system files like configuration data or credentials. This could lead to the exposure of private information and further compromise of the system.
Technical details
The http_request tool in rt-claw (specifically within claw/services/tools/net.c) fails to validate the URL scheme of user-provided input before passing it to the underlying network library (libcurl on Linux). Because the application does not enforce an allowlist of protocols (e.g., http:// or https://), an attacker can use the file:// scheme to perform a local file disclosure. The vulnerability is reachable via the claw_net_get and claw_net_post functions. A remote attacker influencing AI tool arguments can cause the process to read local files and return their contents in the tool's response body. As of the advisory date, no official patch has been released by the vendor.
Affected products
- zevorn rt-claw up to 0.2.0
Timeline
- 2026-07-18: disclosed: Issue reported to the project maintainers via GitHub.
- 2026-07-19: advisory: Vulnerability published in NVD/VulDB.