CVE-2026-16204 is a low-severity vulnerability in zevorn rt-claw up to 0.2.0. A security flaw has been discovered in the tool_run_script_execute function of the claw/services/tools/script.c file, which is part of the Telegram-to-AI Tool Execution Flow. This flaw allows for code injection and can be exploited remotely. The vulnerability affects users of zevorn rt-claw up to version 0.2.0 and has a CVSS sco [truncated]
A vulnerability was found in zevorn rt-claw up to 0.2.0. The function claw_net_get/claw_net_post in claw/services/tools/net.c of the http_request component can result in information disclosure. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed early but has not responded yet. This vulnerability affects the http_request component of zevorn rt- [truncated]
A vulnerability was found in zevorn rt-claw up to 0.2.0. The function claw_tool_invoke in claw/services/swarm/swarm.c, part of the RPC Handler component, is affected. The issue involves incorrect authorization. Remote exploitation is possible. The exploit has been publicly disclosed but vendor response is pending. Users of zevorn rt-claw up to version 0.2.0 should assess and mitigate this vulnerability. S [truncated]
A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an i [truncated]
A vulnerability was determined in zevorn rt-claw up to 0.2.0, affecting the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authorization. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vulnerability allows for incorrect authorization, which can b [truncated]
A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation of the argument url results in server-side request forgery. The attack can be executed remotely. This server-side request forgery vulnerability in zevorn rt-claw up to 0.2.0 allows attackers to make un [truncated]