PatchSiren cyber security CVE debrief
CVE-2026-15626 nextlevelbuilder CVE debrief
A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_bridge.go of the component ACP ToolBridge Workspace Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely.
- Vendor
- nextlevelbuilder
- Product
- GoClaw
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-14
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-14
Who should care
Users of nextlevelbuilder GoClaw 3.13.3-beta.3 should review and apply patches to prevent path traversal attacks.
Technical summary
The vulnerability is caused by a path traversal issue in the writeFile function of the internal/providers/acp/tool_bridge.go file in the ACP ToolBridge Workspace Handler component of nextlevelbuilder GoClaw 3.13.3-beta.3. The attack can be carried out remotely.
Defensive priority
Low priority due to CVSS score of 2.1
Recommended defensive actions
- Review and apply patches for nextlevelbuilder GoClaw 3.13.3-beta.3
- Monitor for remote attacks
- Implement compensating controls for path traversal
Evidence notes
Evidence is limited. Verify vulnerability details with nextlevelbuilder. Check inventory for affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15626 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15626
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15626 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15626
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nextlevelbuilder/goclaw/
-
Source reference
Unverified legacy reference
URL: https://github.com/nextlevelbuilder/goclaw/issues/1201
-
Source reference
Unverified legacy reference
URL: https://github.com/nextlevelbuilder/goclaw/issues/1201
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-15626
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/855805
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/378128
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/378128/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.