---
id: CVE-2026-10219
aliases:
  - GHSA-6jm8-4fhr-5w64
title: GoClaw has a Command Injection issue
summary: GoClaw has a Command Injection issue
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: nextlevelbuilder
product: github.com/nextlevelbuilder/goclaw
ecosystem: go
affected:
  - github.com/nextlevelbuilder/goclaw <= 3.11.3
published: '2026-06-01'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6jm8-4fhr-5w64'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10219'
  - url: 'https://github.com/nextlevelbuilder/goclaw/issues/1121'
  - url: 'https://github.com/nextlevelbuilder/goclaw/pull/1155'
  - url: 'https://github.com/nextlevelbuilder/goclaw'
  - url: 'https://vuldb.com/cve/CVE-2026-10219'
  - url: 'https://vuldb.com/submit/821939'
  - url: 'https://vuldb.com/vuln/367498'
  - url: 'https://vuldb.com/vuln/367498/cti'
tags:
  - osv
  - go
epss: 0.01336
epssPercentile: 0.69988
ingestedAt: '2026-07-10T18:56:50.759Z'
---

## Overview

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

## Affected packages

- `github.com/nextlevelbuilder/goclaw <= 3.11.3`

## Remediation

Refer to the advisory for the patched release.
