


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the …
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 16:08:13
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A remote OS command injection vulnerability (CVE-2026-10219) was discovered in nextlevelbuilder GoClaw versions up to 3.11.3. The vulnerability affects the FsBridge.WriteFile function in the internal/sandbox/fsbridge.go file of the write_file Tool component. Attackers can exploit this vulnerability remotely through manipulation to achieve command injection. The exploit has been publicly disclosed and is available for use. A pull request containing a fix has been submitted but is still awaiting acceptance, leaving systems vulnerable in the interim.
Technical details
Mitigation steps:
Affected products:
GoClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10219
https://github.com/nextlevelbuilder/goclaw/
https://github.com/nextlevelbuilder/goclaw/issues/1121
https://github.com/nextlevelbuilder/goclaw/pull/1155
https://vuldb.com/cve/CVE-2026-10219
https://vuldb.com/submit/821939
https://vuldb.com/vuln/367498
https://vuldb.com/vuln/367498/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
