Junglewise Threat Intelligence

CVE-2026-18038: nextlevelbuilder GoClaw Information Disclosure in jq Handler

CVE-2026-18038 · Severity: medium · CVSS 4.3 · Published 2026-07-28

Technologies: Nextlevelbuilder GoClaw. Vendors: Nextlevelbuilder.

Executive brief

GoClaw, an AI agent deployment platform, contains a security flaw that allows authenticated users with 'operator' privileges to steal sensitive system credentials. By using specifically crafted commands through the platform's built-in tools, an attacker can extract the gateway's secret access tokens. These stolen tokens could then be used to gain broader control over the entire GoClaw environment, potentially compromising customer data and AI operations.

Technical details

An information disclosure vulnerability exists in GoClaw up to version 3.13.2 within the `ExecTool.Execute` function of `internal/http/tools_invoke.go`. When the platform is configured with `tools.execApproval.security=full` and `tools.execApproval.ask=on-miss`, the `jq` binary is treated as a 'safe' executable and is auto-approved for execution. However, the host execution environment fails to scrub sensitive variables like `GOCLAW_GATEWAY_TOKEN` and `GOCLAW_ENCRYPTION_KEY` before spawning the child process. An authenticated attacker with at least 'operator' privileges can invoke `jq` to read these environment variables, bypassing shell-based deny patterns. This allows for credential exfiltration and subsequent privilege escalation against the gateway APIs. A fix was introduced in pull request 1230.

Affected products

  • nextlevelbuilder GoClaw <= 3.13.2

Timeline

  • 2026-06-13: other: Vulnerability reproduction and PoC confirmed
  • 2026-06-15: patched: Fix merged via PR 1230
  • 2026-07-28: disclosed: CVE-2026-18038 published

References

Related threats