Technology · Nextlevelbuilder
Nextlevelbuilder GoClaw vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in Nextlevelbuilder GoClaw: 0 in the last 7 days and 13 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18038, was published on 28 July 2026.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 0
- Exploited in the wild
- 0
About Nextlevelbuilder GoClaw
GoClaw is a library for the Go programming language designed to facilitate web scraping and data extraction.
Latest Nextlevelbuilder GoClaw vulnerabilities
- CVE-2026-18038: nextlevelbuilder GoClaw Information Disclosure in jq HandlermediumCVSS 4.3
- CVE-2026-16199: nextlevelbuilder GoClaw authorization bypass in ExecTool.ExecutemediumCVSS 6.3
- CVE-2026-16124: nextlevelbuilder GoClaw SSRF in web_fetch componentmediumCVSS 6.3
- CVE-2026-16123: nextlevelbuilder GoClaw authorization bypass in ToolsInvokeHandlermediumCVSS 6.3
- CVE-2026-16122: nextlevelbuilder GoClaw authorization bypass in exec approval flowmediumCVSS 4.3
- CVE-2026-16121: nextlevelbuilder GoClaw improper authorization in exec tool approval managermediumCVSS 6.3
- CVE-2026-16120: nextlevelbuilder GoClaw command execution bypass via basename collisionmediumCVSS 6.3
- CVE-2026-16119: nextlevelbuilder GoClaw incorrect authorization in WebSocket Approval EndpointmediumCVSS 6.3
- CVE-2026-15627: nextlevelbuilder GoClaw local file disclosure in browser toolmediumCVSS 4.3
- CVE-2026-15626: nextlevelbuilder GoClaw path traversal in ACP ToolBridge Workspace HandlermediumCVSS 6.3
- CVE-2026-15625: nextlevelbuilder GoClaw command execution bypass in ExecApprovalManagermediumCVSS 6.3
- CVE-2026-15624: nextlevelbuilder GoClaw SSRF in bytePlusDownloadVideomediumCVSS 6.3
- CVE-2026-14716: nextlevelbuilder GoClaw incorrect authorization in WebSocket RPC HandlermediumCVSS 6.3
- CVE-2026-10617: nextlevelbuilder GoClaw missing authentication in resolveAuthhighCVSS 7.3
- CVE-2026-10616: nextlevelbuilder GoClaw authorization bypass in TeamTasksToolmediumCVSS 4.3
- CVE-2026-10583: nextlevelbuilder GoClaw SSRF in TTS Configuration EndpointmediumCVSS 4.7
- CVE-2026-10219: nextlevelbuilder GoClaw OS command injection in FsBridge.WriteFilehighCVSS 7.3EPSS 1.3%
- CVE-2026-10218: nextlevelbuilder GoClaw authorization bypass in evolution_handlersmediumCVSS 5.4
- CVE-2026-10217: nextlevelbuilder GoClaw improper privilege management in RoleAdmin GatewaymediumCVSS 6.3
Most severe Nextlevelbuilder GoClaw vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-10219: nextlevelbuilder GoClaw OS command injection in FsBridge.WriteFilehighCVSS 7.3EPSS 1.3%
- CVE-2026-10617: nextlevelbuilder GoClaw missing authentication in resolveAuthhighCVSS 7.3
- CVE-2026-16199: nextlevelbuilder GoClaw authorization bypass in ExecTool.ExecutemediumCVSS 6.3
- CVE-2026-16124: nextlevelbuilder GoClaw SSRF in web_fetch componentmediumCVSS 6.3
- CVE-2026-16123: nextlevelbuilder GoClaw authorization bypass in ToolsInvokeHandlermediumCVSS 6.3
- CVE-2026-16121: nextlevelbuilder GoClaw improper authorization in exec tool approval managermediumCVSS 6.3
- CVE-2026-16120: nextlevelbuilder GoClaw command execution bypass via basename collisionmediumCVSS 6.3
- CVE-2026-16119: nextlevelbuilder GoClaw incorrect authorization in WebSocket Approval EndpointmediumCVSS 6.3
- CVE-2026-15626: nextlevelbuilder GoClaw path traversal in ACP ToolBridge Workspace HandlermediumCVSS 6.3
- CVE-2026-15625: nextlevelbuilder GoClaw command execution bypass in ExecApprovalManagermediumCVSS 6.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 11 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/goclaw.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Nextlevelbuilder GoClaw vulnerabilities", https://junglewise.ai/threats/technologies/goclaw, 26 September 2026.